当前位置:   article > 正文

samba开启用户审计_samba出用户日志

samba出用户日志

1./etc/samba/smb.conf添加如下配置:

global:

  1. [global]
  2. workgroup = SAMBA
  3. security = user
  4. passdb backend = tdbsam
  5. printing = cups
  6. printcap name = cups
  7. load printers = yes
  8. cups options = raw
  9. log file = /var/log/samba/%m.log
  10. log level = 5 vfs:10 # 定义日志级别
  11. vfs object = vfs
  12. vfs object = full_audit #开启审计
  13. full_audit:prefix = %u|%I|%S
  14. full_audit:failure = connect chdir #审计失败的动作
  15. full_audit:success = mkdir rmdir rename unlink pwrite_send pwrite_recv pread_recv pread_send #审计成功的动作
  16. #full_audit:success = mkdir rmdir rename unlink pwrite pread sendfile recvfile
  17. full_audit:facility = local5 #审计日志保存位置设置
  18. full_audit:priority = notice #定义日志级别

共享目录:

  1. [share]
  2. comment = share
  3. path = /home/share
  4. public = no
  5. writable = yes
  6. vfs object = vfs
  7. vfs object = full_audit #该目录开启审计

2.日志输出设置:/etc/rsyslog.conf

local5.*						/var/log/samba/audit.log

3.审计日志如下:

  1. [root@lrh001 ~]# tail -f /var/log/samba/audit.log
  2. May 17 15:44:09 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_send|ok|/home/share/jishubu/1.txt
  3. May 17 15:44:09 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_recv|ok|/home/share/jishubu/1.txt
  4. May 17 15:44:14 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_send|ok|/home/share/jishubu/新建文本文档 (2).txt
  5. May 17 15:44:14 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_recv|ok|/home/share/jishubu/新建文本文档 (2).txt
  6. May 17 15:44:23 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_send|ok|/home/share/yewu/yewu.txt
  7. May 17 15:44:23 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_recv|ok|/home/share/yewu/yewu.txt
  8. May 17 15:44:31 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_send|ok|/home/share/yewu/yewu.txt
  9. May 17 15:44:31 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_recv|ok|/home/share/yewu/yewu.txt
  10. May 17 15:51:43 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_send|ok|/home/share/yewu/yewu.txt
  11. May 17 15:51:43 lrh001 smbd_audit: lrh|192.170.1.143|share|pread_recv|ok|/home/share/yewu/yewu.txt

声明:本文内容由网友自发贡献,不代表【wpsshop博客】立场,版权归原作者所有,本站不承担相应法律责任。如您发现有侵权的内容,请联系我们。转载请注明出处:https://www.wpsshop.cn/w/凡人多烦事01/article/detail/184114?site
推荐阅读
相关标签
  

闽ICP备14008679号