ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Log all users activity on server

    IT Discussion
    linux shell logging
    3
    19
    3.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      OK I just looked at the OPs link about auditing - that article talks about auditing changes made on a Linux box.

      I think something similar can be done in windows, but it's a lot harder.

      AmbarishrhA 1 Reply Last reply Reply Quote 0
      • AmbarishrhA
        Ambarishrh @Dashrender
        last edited by

        So wanted to know if this is the best way to log all activities or can this be pushed to ELK to have a better view or an alternate solution/method?

        scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @Ambarishrh
          last edited by

          @Ambarishrh said:

          So wanted to know if this is the best way to log all activities or can this be pushed to ELK to have a better view or an alternate solution/method?

          ELK is almost certainly best. The range of functionality is just too good to pass up.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @Ambarishrh
            last edited by

            @Ambarishrh
            For Linux, logging will give you what you want - and you can push the information to a ELK box or use Logg.ly or others.

            But again, there is no way to do this in windows, at least not like a command line logging in Linux.
            In the link, you're recording all of the commands they are typing at the command line, but users don't do this in Windows, they live inside apps.

            What is your end goal?

            AmbarishrhA 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              Yeah, GUIs can't be logged so cleanly. Do you want Windows desktop logging? You pretty much need a screen recorder to get the level that Linux tends to get.

              1 Reply Last reply Reply Quote 0
              • AmbarishrhA
                Ambarishrh @Dashrender
                last edited by

                @Dashrender My end goal is to log all activity on our Linux Servers, no Windows

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Ambarishrh
                  last edited by

                  @Ambarishrh said:

                  @Dashrender My end goal is to log all activity on our Linux Servers, no Windows

                  Oh okay, ELK and process accounting is pretty good. There is no simple way of getting everything at a user level. Do you have Linux GUIs or text only?

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    I know places that have required this and the complexity gets crazy.

                    1 Reply Last reply Reply Quote 0
                    • AmbarishrhA
                      Ambarishrh
                      last edited by

                      We don't have Linux GUI, it has cPanel but we manage servers using command majority of the time. Bringing in Ansible to automate the whole setup process and this way I am even getting the GUI configuration using cPanel commands and scripts.

                      So ELK + the logging using the link on my first post does the trick!

                      I am also checking https://www.graylog.org/ as this seems to be pretty famous and looks like a good alternative to ELK if anyone else looking at it.

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        What people tend to do for what you want is something like a forced screen session to log commands as typed or to use a jump box that captures all activity.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Ambarishrh
                          last edited by

                          @Ambarishrh said:

                          I am also checking https://www.graylog.org/ as this seems to be pretty famous and looks like a good alternative to ELK if anyone else looking at it.

                          Graylog is built on the same foundation as ELK. They are both log ingesting and interfaces applied on top of Elasticsearch.

                          AmbarishrhA 1 Reply Last reply Reply Quote 1
                          • AmbarishrhA
                            Ambarishrh @scottalanmiller
                            last edited by

                            @scottalanmiller said:

                            @Ambarishrh said:

                            I am also checking https://www.graylog.org/ as this seems to be pretty famous and looks like a good alternative to ELK if anyone else looking at it.

                            Graylog is built on the same foundation as ELK. They are both log ingesting and interfaces applied on top of Elasticsearch.

                            Have you tried Graylog?

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Ambarishrh
                              last edited by

                              @Ambarishrh said:

                              @scottalanmiller said:

                              @Ambarishrh said:

                              I am also checking https://www.graylog.org/ as this seems to be pretty famous and looks like a good alternative to ELK if anyone else looking at it.

                              Graylog is built on the same foundation as ELK. They are both log ingesting and interfaces applied on top of Elasticsearch.

                              Have you tried Graylog?

                              No, on my long list of things to build.

                              1 Reply Last reply Reply Quote 0
                              • 1 / 1
                              • First post
                                Last post