Full Command Logging?

  • humbletech99
  • Proficient
  • Proficient
  • User avatar
  • Joined: Mar 09, 2006
  • Posts: 300
  • Status: Offline

Post January 28th, 2009, 9:57 am

I am looking for a really good command logging tool to improve the auditing of my servers. I have previously used snoopy but this is currently a bit flaky and causing serious problems for me, it doesn't look like it's been maintained since 2004, it didn't even want to compile until I added -fPIC but it's causing segmentation faults and just ruins my test systems, eventually causing all or nearly all commands to segfault.

I've tried the process account tools but they log only the command basename, no args and no shell built-ins either (although even snoopy doesn't get that last one, but I could live without it if I had to). Shell history files are not security, they are just convenience, so they don't fit either (unless we find a way of capturing all shell history straight into syslog...)

So I'm looking for something else that I can deploy among my servers to fully audit any commands entered and log them via syslog.

Does anyone have any recommendations for a good thorough command logger, capturing args as well?
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post January 28th, 2009, 9:57 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post January 28th, 2009, 10:15 am

It seems to me that you want a keylogger for *nix. I came across uberkey while searching. I don't if it's any good.
How do you know when a politician is lying? His mouth is moving.
  • humbletech99
  • Proficient
  • Proficient
  • User avatar
  • Joined: Mar 09, 2006
  • Posts: 300
  • Status: Offline

Post January 28th, 2009, 10:37 am

I gave uberkey a try but it doesn't seem like a fully fledged application and it didn't log anything, I think it only captures the local keyboard and not all commands ie over ssh where most of the stuff happens on servers.
  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post January 28th, 2009, 10:39 am

If I find anything else, I'll let you know.
How do you know when a politician is lying? His mouth is moving.

Post Information

  • Total Posts in this topic: 4 posts
  • Users browsing this forum: No registered users and 59 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.