Los sistemas Linux son populares en muchas organizaciones, y la auditoría de syslogs de los sistemas Linux puede proporcionar información importante sobre los eventos en su red. Esta información le ayudará a decidir sobre varias acciones administrativas y de seguridad. La auditoría de sistemas Linux involucra:
La auditoría de sistemas Linux ofrece un control completo sobre la seguridad y administración de su red, pero no es tan simple. En cambio, usted puede utilizar EventLog Analyzer, una solución integral de administración de syslog, para mantener un sistema Linux seguro.
Informes disponibles
User logons | SU logons | SSH logons | FTP or SFTP logons | Logon overview | Top logons based on user | Top logons based on device | Top logons based on remote device | Top Linux logon method | Logon trend | User logoffs | SU logoffs | SSH logoffs | FTP or SFTP logoffs | Logoff overview
Informes disponibles
User failed logons | SU failed logons | SSH failed logons | FTP or SFTP failed logons | Failed logons overview | Top failed logons based on user | Top failed logons based on device | Top failed logons based on remote device | Top failed logon methods | Failed logon trends | Repeated authentication failures | Invalid user logon attempts | Unsuccessful logon failures with long password | Repeated logon failure based on remote device | Repeated authentication failures based on remote device
Informes disponibles
Added user accounts | Deleted user accounts | Renamed user accounts | Groups added | Groups deleted | Groups renamed | Password changes | Failed password changes | Failed user additions | Top Linux account management events
Informes disponibles
USB plugged in | USB taken out
Informes disponibles
SUDO command executions | Failed SUDO command executions | Top SUDO command executions | Top failed SUDO command executions
Informes disponibles
Emails sent overview | Emails received overview | Top emails sent based on sender | Top emails sent based on remote device | Top emails received from remote devices | Top sender domain | Top recipient domain | Trend report on emails sent | Trend report on emails received | Top emails rejected based on sender | Top receivers who rejected emails | Top email rejection errors | Top rejected domains | Emails rejected overview | Mailbox unavailable | Insufficient storage | Bad sequence of commands | Bad email Address | Nonexistent email address on remote side | Top email errors | Top email errors based on sender | Failed email deliveries
Informes disponibles
Reverse lookup errors | Bad deviceConfig errors | Bad ISP errors | Invalid connection remote device | Denial of service attack
Informes disponibles
Successful NFS mounts | Refused NFS mounts | Denied NFS mounts based on users | Top successful NFS mounts based on remote device | Top refused NFS mounts based on remote device.
Informes disponibles
Cron Jobs | Cron Edit | Cron Job Started | Cron Job Terminated | Connection aborted by a software | Receive identification string | Session connected | Session disconnected | Deactivated services | Unsupported protocol version | Timeout while logging | Failed updates | deviceName mismatch error | deviceAddress mismatch error
Informes disponibles
File downloads | File uploads | Data transfer stall timeouts | Logon timeouts | Session idle timeouts | No transfer timeouts | Connection timeouts | FTP reports overview | Top FTP operations based on user | Top FTP operations based on remote device
Informes disponibles
Syslog service stopped | Syslog service restarted | Low disk space | System shutdown | Yum installs | Yum updates | Yum uninstalls
Informes disponibles
Emergency events | Alert events | Critical events | Error events | Warning events | Notice events | Information events | Debug events
Informes disponibles
Criticality level of events | Critical reports based on event | Critical events based on device | Critical events based on remote device | Critical event trends | Critical events overview