Hey,
I'm working on developing a Misuse detection system.For this i make use of
the audit data generated in syslog file.The problem here is it does'nt
record all information that i want.For instance when somebody fingers from
a remote host ... the syslog does'nt record the target user name.
Eg: disney/Ram$ finger sharat@ra
here: disney -> source machine Ram -> source user
ra -> target machine sharat -> target user
I want to log the target user name also,how do i do that.
Thanks,
Sharat.
This archive was generated by hypermail 2.1.3 : Wed Mar 20 2002 - 19:05:36 CET