Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

²Ù×÷ϵͳ

Vista | Windows 9X | Windows Server | Linux&Uinx | FreeBSD | ÆäËü²Ù×÷ϵͳ |
Ê×Ò³ > ²Ù×÷ϵͳ > Linux&Uinx > LinuxϵͳÖÐLogcheckµÄ°²×°ºÍÅäÖà > ÕýÎÄ

LinuxϵͳÖÐLogcheckµÄ°²×°ºÍÅäÖÃ

³ö´¦£º×ªÔØ ×÷Õߣº×ªÔØ Ê±¼ä£º2006-5-30 14:09:00

¸ÅÊö
¡¡¡¡ ±£Ö¤ÏµÍ³°²È«µÄÒ»ÏîºÜÖØÒªµÄ¹¤×÷¾ÍÊǶ¨ÆÚ²é¿´ÈÕÖ¾Îļþ¡£ÏµÍ³¹ÜÀíÔ±Ò»°ã±È½Ï棬ûÓÐʱ¼ä¶¨ÆÚÍê³ÉÕâÏ×÷£¬ÕâÑù¾Í¿ÉÄÜ´øÀ´Ò»Ð©°²È«ÎÊÌâ¡£

ÏÂÃæÊÇLogcheck¸ÅÀ¨ÐԵĽéÉÜ£º

ÉóºËºÍ¼Ç¼ϵͳµÄʼþÊǷdz£ÖØÒªµÄ¡£ÌرðÊǵ±ÄãµÄ¼ÆËã»úÁ¬½Óµ½InternetÉÏÖ®ºó£¬ÏµÍ³¹ÜÀíÔ±Èç¹û¶Ô¡°Òì³£¡±µÄʼþ±£³Ö¾¯¾õ£¬¾ÍÄÜ·Àֹϵͳ±»ÈëÇÖ¡£ÔÚUnixϵͳÖÐÈç¹û½ö½ö°Ñϵͳʼþ×÷ΪÈÕÖ¾¼Ç¼ÏÂÀ´£¬¶ø²»È¥²é¿´£¬»¹ÊÇÎÞ¼ÃÓÚÊ¡£Logchek¿ÉÒÔ×Ô¶¯µØ¼ì²éÈÕÖ¾Îļþ£¬ÏȰÑÕý³£µÄÈÕÖ¾ÐÅÏ¢ÌÞ³ýµô£¬°ÑһЩÓÐÎÊÌâµÄÈÕÖ¾±£ÁôÏÂÀ´£¬È»ºó°ÑÕâЩÐÅÏ¢email¸øÏµÍ³¹ÜÀíÔ±¡£Logcheck±»Éè¼Æ³É×Ô¶¯ÔËÐУ¬¶¨ÆÚ¼ì²éÈÕÖ¾ÎļþÒÔ·¢ÏÖÎ¥·´°²È«¹æÔòÒÔ¼°Òì³£µÄ»î¶¯¡£LogcheckÓÃlogtail³ÌÐò¼ÇסÉÏ´ÎÒѾ­¶Á¹ýµÄÈÕÖ¾ÎļþµÄλÖã¬È»ºó´ÓÕâ¸öλÖÿªÊ¼´¦ÀíеÄÈÕÖ¾ÐÅÏ¢¡£

×¢ÒâÊÂÏî
¡¡¡¡ ÏÂÃæËùÓеÄÃüÁî¶¼ÊÇUnix¼æÈݵÄÃüÁî¡£

Դ·¾¶¶¼Îª¡°/var/tmp¡±£¨µ±È»ÔÚʵ¼ÊÇé¿öÖÐÒ²¿ÉÒÔÓÃÆäËü·¾¶£©¡£

°²×°ÔÚRedHat Linux 6.1ºÍ6.2ϲâÊÔͨ¹ý¡£

ÒªÓá°root¡±Óû§½øÐа²×°¡£

LogcheckµÄ°æ±¾ÊÇ1.1.1¡£

Èí¼þ°üµÄÀ´Ô´
¡¡¡¡ LogcheckµÄÖ÷Ò³£ºhttp://www.psionic.com/abacus/logcheck/¡£

ÏÂÔØ£ºlogcheck-1.1.1.tar.gz¡£

°²×°Èí¼þ°üÐèҪעÒâµÄÎÊÌâ
¡¡¡¡ ×îºÃÔÚ±àÒëǰºÍ±àÒëºó¶¼×öÒ»ÕÅϵͳÖÐËùÓÐÎļþµÄÁÐ±í£¬È»ºóÓá°diff¡±ÃüÁîÈ¥±È½ÏËüÃÇ£¬ÕÒ³öÆäÖеIJî±ð²¢ÖªµÀµ½µ×°ÑÈí¼þ°²×°ÔÚÄÄÀï¡£Ö»Òª¼òµ¥µØÔÚ±àÒë֮ǰÔËÐÐÒ»ÏÂÃüÁî¡°find /* >Logcheck1¡±£¬ÔÚ±àÒëºÍ°²×°ÍêÈí¼þÖ®ºóÔËÐÐÃüÁî¡°find /* > Logcheck2¡±£¬×îºóÓÃÃüÁî¡°diff Logcheck1 Logcheck2 > Logcheck-Installed¡±ÕÒ³ö±ä»¯¡£

½âѹÈí¼þ°ü
¡¡¡¡ °ÑÈí¼þ°ü£¨tar.gz£©½âѹ£º

[root@deep /]# cp logcheck-version.tar.gz /var/tmp/
¡¡¡¡ [root@deep /]# cd /var/tmp
¡¡¡¡ [root@deep tmp]# tar xzpf logcheck-version.tar.gz

±àÒëºÍÓÅ»¯
¡¡¡¡ ±ØÐëÐ޸ġ°Makefile¡±Îļþ£¬ÉèÖÃLogcheckµÄ°²×°Â·¾¶¡¢±àÒë±ê¼Ç£¬»¹Òª¸ù¾ÝÄãµÄϵͳ½øÐÐÓÅ»¯¡£±ØÐë¸ù¾ÝRedHatµÄÎļþϵͳ½á¹¹À´Ð޸ġ°Makefile¡±Îļþ£¬²¢ÇÒÔÚ¡°PATH¡±»·¾³±äÁ¿µÄÉ趨µÄ·¾¶Öа²×°LogcheckµÄ½Å±¾Îļþ¡£

µÚÒ»²½

תµ½LogcheckËùÔÚµÄĿ¼¡£

±à¼­¡°Makefile¡±Îļþ£¨vi Makefile£©²¢¸Ä±äÏÂÃæÕâЩÐУº

CC = cc

¸ÄΪ£º

CC = egcs

CFLAGS = -O

¸ÄΪ£º

CFLAGS = -O9 -funroll-loops -ffast-math -malign-double -mcpu=pentiumpro -march=pentiumpro -fomit-frame-pointer -fno-exceptions

INSTALLDIR = /usr/local/etc

¸ÄΪ£º

INSTALLDIR = /etc/logcheck

INSTALLDIR_BIN = /usr/local/bin

¸ÄΪ£º

INSTALLDIR_BIN = /usr/bin

INSTALLDIR_SH = /usr/local/etc

¸ÄΪ£º

INSTALLDIR_SH = /usr/bin

TMPDIR = /usr/local/etc/tmp

¸ÄΪ£º

TMPDIR = /etc/logcheck/tmp

ÉÏÃæÕâЩÐÞ¸ÄÊÇΪÁ˰ѡ°Makefile¡±ÅäÖÃΪʹÓá°egcs¡±±àÒëÆ÷£¬Ê¹ÓÃÊÊÓ¦ÓÚÎÒÃÇϵͳµÄ±àÒëÓÅ»¯±ê¼Ç£¬²¢ÇÒ°ÑLogcheckµÄ°²×°Ä¿Â¼ÉèÖóÉ×ñÑ­RedHatµÄÎļþϵͳ½á¹¹¡£

µÚ¶þ²½

±à¼­¡°Makefile¡±Îļþ£¨vi +67 Makefile£©¸Ä±äÏÂÃæÕâЩÐУº

@if [ ! -d $(TMPDIR) ]; then /bin/mkdir $(TMPDIR); fi

¸ÄΪ£º

@if [ ! -d $(TMPDIR) ]; then /bin/mkdir -p $(TMPDIR); fi

¼ÓÉÏ¡°-p¡±²ÎÊýÊÇÈð²×°³ÌÐò¸ù¾ÝÐèÒª×Ô¶¯´´½¨Ä¿Â¼¡£

µÚÈý²½

°²×°Logcheck£º

[root@deep logcheck-1.1.1]# make linux

ÉÏÃæµÄÃüÁîΪLinux²Ù×÷ϵͳÅäÖÃLogcheck£¬È»ºó°ÑÔ´Îļþ±àÒë³É¶þ½øÖÆÎļþ£¬×îºó°Ñ¶þ½øÖÆÎļþºÍÅäÖÃÎļþ¿½±´µ½ÏàÓ¦µÄĿ¼¡£

Çå³ý²»±ØÒªµÄÎļþ
¡¡¡¡ ÓÃÏÂÃæµÄÃüÁîɾ³ý²»±ØÒªµÄÎļþ£º

[root@deep /]# cd /var/tmp
¡¡¡¡ [root@deep tmp]# rm -rf logcheck-version/ logcheck-version_tar.gz

¡°rm¡±ÃüÁîɾ³ýËùÓбàÒëºÍ°²×°LogcheckËùÐèÒªµÄÔ´³ÌÐò£¬²¢ÇÒ°ÑLogcheckÈí¼þµÄѹËõ°üɾ³ýµô¡£

ÅäÖá°/usr/bin/logcheck.sh¡±Îļþ
¡¡¡¡ ÒòΪÎÒÃDz»Ê¹Óá°/usr/local/etc¡±Õâ¸ö·¾¶£¬ËùÒÔ±ØÐë¸Ä±ä¡°logcheck.hacking¡±¡¢¡°logcheck.violations¡±¡¢¡°logcheck.ignore¡±¡¢¡°logcheck.violations.ignore¡±ºÍ¡°logtail¡±ÖÐËùÓеÄ·¾¶µ½Òª¸Ä±ä¡£LogcheckµÄ½Å±¾Îļþ¡°/usr/bin/logcheck.sh¡±ÔÊÐíÉèÖÃһЩѡÏ¿ÉÒԸıä·¾¶ºÍ³ÌÐòµÄÔËÐС£ÕâЩ¶¼ÓÐÏêϸµÄ×¢ÊÍ£¬Ò²ºÜ¼òµ¥¡£

µÚÒ»²½

±à¼­¡°logcheck.sh¡±Îļþ£¨vi /usr/bin/logcheck.sh£©²¢ÇҸı䣺

LOGTAIL=/usr/local/bin/logtail

¸ÄΪ£º

LOGTAIL=/usr/bin/logtail

TMPDIR=/usr/local/etc/tmp

¸ÄΪ£º

TMPDIR=/etc/logcheck/tmp

HACKING_FILE=/usr/local/etc/logcheck.hacking

¸ÄΪ£º

HACKING_FILE=/etc/logcheck/logcheck.hacking

VIOLATIONS_FILE=/usr/local/etc/logcheck.violations

¸ÄΪ£º

VIOLATIONS_FILE=/etc/logcheck/logcheck.violations

VIOLATIONS_IGNORE_FILE=/usr/local/etc/logcheck.violations.ignore

¸ÄΪ£º

VIOLATIONS_IGNORE_FILE=/etc/logcheck/logcheck.violations.ignore

IGNORE_FILE=/usr/local/etc/logcheck.ignore

¸ÄΪ£º

IGNORE_FILE=/etc/logcheck/logcheck.ignore

µÚ¶þ²½

°ÑLogcheck·Åµ½crontabÖУ¬Ê¹Ö®³ÉΪcronjob£º

°²×°ÍêLogcheckÖ®ºó£¬±ØÐëÒÔ¡°root¡±È¨Ïޱ༭±¾µØµÄ¡°crontab¡±Îļþ£¬²¢°ÑLogcheckÉèÖóÉÿСʱÔËÐÐÒ»´Î£¨µ±È»ÄãÒ²¿ÉÒÔ°Ñʱ¼äÉ賤һµã»òÕßÉè¶ÌÒ»µã£©¡£

l ÓÃÏÂÃæµÄÃüÁî±à¼­crontab£º

[root@deep /]# crontab -e

# Hourly check Log files for security violations and unusual activity.
¡¡¡¡ 00 * * * * /usr/bin/logcheck.sh

×¢Ò⣺Èç¹ûûÓбØÒªµÄ»°£¬LogcheckÊDz»»áÓÃemail±¨¸æÈκζ«Î÷µÄ¡£

°²×°µ½ÏµÍ³ÖеÄÎļþ
¡¡¡¡ > /etc/logcheck
¡¡¡¡ > /usr/bin/logcheck.sh
¡¡¡¡ > /etc/logcheck/tmp
¡¡¡¡ > /etc/logcheck/logcheck.hacking
¡¡¡¡ > /etc/logcheck/logcheck.violations
¡¡¡¡ > /etc/logcheck/logcheck.violations.ignore
¡¡¡¡ > /etc/logcheck/logcheck.ignore
¡¡¡¡ > /usr/bin/logtail
¡¡¡¡ > /var/log/messages.offset
¡¡¡¡ > /var/log/secure.offset
¡¡¡¡ > /var/log/maillog.offset

°æÈ¨ËµÃ÷
¡¡¡¡ ÕâÆªÎÄÕ·­ÒëºÍ¸Ä±à×ÔGerhard MouraniµÄ¡¶Securing and Optimizing Linux: RedHat Edition¡·£¬Ô­Îļ°Æä°æÈ¨Ð­ÒéÇë²Î¿¼£ºwww.openna.com¡£

Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • ÓÃLVM¹ÜÀíLinuxϵͳ·þÎñÆ÷´æ´¢¿Õ¼ä
  • Linuxƽ̨ÉÏÇáËɰ²×°ÓëÅäÖÃDomino
  • ʵս£ºÔÚLinuxÏÂÃæÅäÖÃwpa ¿Í»§¶Ë
  • Linux²Ù×÷ϵͳ×îµÄ¹¦ÄÜÊÇʲô£¿
  • ÓÃLinuxϵͳÒýµ¼CDΪ·þÎñÆ÷ÅÅÓǽâÄÑ
  • redhat linux°²×°ºóÔõÑùÓÃÂß¼­¾í
  • ÄܺIJâÊÔ£ºLinuxÓëWindows Server 2008
  • Linux·þÎñÆ÷ADSLÀûÓÃNATʵÏÖÉÏÍø¹²Ïí
  • LinuxÏÂÈçºÎÆÆ½âPHP¼ÓÃÜdezendÈí¼þ
  • ÐÂÊÖѧÌãºÔÚLinuxϰ²×°Perl¼°PerlÄ£¿é
  • Linux hosts.allowÓëhosts.denyÏÞÖÆ·ÃÎÊ
  • LinuxϵͳϵÄÈýÖÖJava»·¾³ÅäÖ÷½·¨
  • linuxµÄ»ù±¾²Ù×÷£¨ÉÏ£©
  • LinuxϵͳÏÂÓ¦ÓÃ֪ʶ´óÜöÝÍ
  • GNU GRUBÆô¶¯¹ÜÀíÆ÷
  • ÖÆ×÷»ùÓÚÈíÅ̵ÄLinuxϵͳ
  • ÍøÂçÅäÖÃÎļþ¿ìËÙ½â¶Á
  • linuxµÄ»ù±¾²Ù×÷£¨Ï£©
  • ÆÊÎöLinuxϵͳÆô¶¯¹ý³Ì
  • DameWareÈþÖÓòÍø¹ÜÀí²»ÔÙ·±Ëö
  • ÔÚRedhat 9ÏÂʵÏÖË«»úÈȱ¸ºÍ¼¯Èº¹¦ÄÜ
  • LINUXÊØ»¤½ø³Ì½éÉÜ
  • Redhat advance server 2.1¼¯ÈºµÄ°²×°Óë¹ÜÀí
  • Linux±ØÐëѧ»áµÄ60¸öÃüÁî-Îļþ´¦Àí
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ