vim rsys.sh
cat >> /etc/profile <<EOF HISTFILESIZE=2000 HISTSIZE=2000 HISTTIMEFORMAT="%Y%m%d-%H%M%S: " export HISTTIMEFORMAT export PROMPT_COMMAND=‘{ command=\$(history 1 | { read x y; echo \$y; }); logger -p local1.notice -t bash -i "user=\$USER,ppid=\$PPID,from=\$SSH_CLIENT,pwd=\$PWD,command:\$command"; }‘ EOF echo "127.0.0.1 secaudit.xf.conf" >>/etc/hosts echo ‘:msg,contains, "Did not receive identification string from 127.0.0.1" ~‘ >>/etc/rsyslog.conf echo "authpriv.* @secaudit.xf.conf" >>/etc/rsyslog.conf echo "local1.notice @secaudit.xf.conf" >>/etc/rsyslog.conf service rsyslog restart
时间: 2024-10-08 00:52:00