简易日志审计

在所有被登录服务器上操作如下内容:

mkdir /usr/local/records
chmod 777 !$
chmod +t !$
# +t 防止被删除

添加环境变量:

vi /etc/profile
if [ ! -d  /usr/local/records/${LOGNAME} ]
then
mkdir -p /usr/local/records/${LOGNAME}
chmod 300 /usr/local/records/${LOGNAME} 
fi
export HISTORY_FILE="/usr/local/records/${LOGNAME}/bash_history"
export PROMPT_COMMAND='{ date "+%Y-%m-%d %T ##### $(who am i |awk "{print \$1\" \"\$2\" \"\$5}") #### $(history 1 | { read x cmd; echo "$cmd"; })"; } >>$HISTORY_FILE'

source /etc/profile

示例:

posted @ 2018-02-07 14:52  luchuangao  阅读(265)  评论(0编辑  收藏  举报