nanog mailing list archives
Re: Future timestamps in /var/log/secure
From: gordon b slater <gordslater () ieee org>
Date: Fri, 26 Feb 2010 18:50:02 +0000
On Fri, 2010-02-26 at 11:29 -0700, Brielle Bruns wrote:
Isn't the timestamps inserted by syslog rather then the reporting program itself?
that's my understanding also (clarification: syslogs of your server have timestamps of your syslegsserver's time, IMHO) eg: on my Debain systems I don't split the logging to /var/log/secure, I can usually handle a large log OK, but it's easy enough to get the authpriv* stuff to log to /v/l/secure if needed. So, my point is, syslogd.conf tells syslogd where to put them, and it stamps the time for each entry.
What syslog do you use - classic (ie: sysklogd) or a modern one like rsyslog? It almost looks like the timezone got changed from local to GMT or similar, then swapped back (as odd as it may sound).
On a cautionary note, I've seen tz-change shenanigans to mask unauthorised access before, so might be a good time to have quick poke around with a tinfoil hat on, just in case. Don't have a heart attack tough, not yet :) Gord -- this .sig space reserved by ITU-T pending clarification of intentions
Current thread:
- Future timestamps in /var/log/secure Wade Peacock (Feb 26)
- Re: Future timestamps in /var/log/secure Brielle Bruns (Feb 26)
- Re: Future timestamps in /var/log/secure Larry Sheldon (Feb 26)
- Re: Future timestamps in /var/log/secure Wade Peacock (Feb 26)
- Re: Future timestamps in /var/log/secure gordon b slater (Feb 26)
- Re: Future timestamps in /var/log/secure Larry Sheldon (Feb 26)
- RE: Future timestamps in /var/log/secure Joe (Feb 26)
- Re: Future timestamps in /var/log/secure gordon b slater (Feb 26)
- Re: Future timestamps in /var/log/secure Wade Peacock (Feb 26)
- Re: Future timestamps in /var/log/secure gordon b slater (Feb 26)
- Re: Future timestamps in /var/log/secure Valdis . Kletnieks (Feb 26)
- Re: Future timestamps in /var/log/secure William Pitcock (Feb 26)
- Re: Future timestamps in /var/log/secure gordon b slater (Feb 26)
- Re: Future timestamps in /var/log/secure William Pitcock (Feb 26)
- Re: Future timestamps in /var/log/secure Seth Mattinen (Feb 26)
- Re: Future timestamps in /var/log/secure Wade Peacock (Feb 26)
- Re: Future timestamps in /var/log/secure Brielle Bruns (Feb 26)
- <Possible follow-ups>
- Re: Future timestamps in /var/log/secure Brielle Bruns (Feb 26)
