| Syslog | /var/log/syslog (Debian) or /var/log/messages (RHEL) | System-wide logs, service messages |
| Authentication | /var/log/auth.log or /var/log/secure | Logins, sudo, su, SSH, PAM events |
| Last Logins | /var/log/lastlog, /var/log/wtmp, /var/log/btmp | Successful & failed logins |
| Cron Logs | /var/log/cron or in syslog | Scheduled tasks run by cron |
| Kernel Ring Buffer | dmesg or /var/log/dmesg | Boot and hardware messages |
| Audit Logs | /var/log/audit/audit.log | SELinux, policy violations, syscall audits (if auditd enabled) |
Announcement
Collapse
No announcement yet.
Log Files
Collapse
X
-
Log Files
Tags: None