File: //opt/BCLinux/bse/secure_set/s17_syslogLogin
#!/bin/sh
#=====================================================================
InsertSection "Recording the login events..."
if [ $RECORDING_LOGIN_EVENTS -eq 1 ]; then
if [ -f /etc/rsyslog.conf ];then
cp -np /etc/rsyslog.conf /etc/rsyslog.conf_bak
fi
if [ -f /etc/syslog.conf ];then
cp -np /etc/syslog.conf /etc/syslog.conf_bak
fi
#--------------recording the login events--------------
IS_EXIST=`egrep -v '^$|^#' /etc/rsyslog.conf | grep -E '^authpriv.info' | grep "authpriv.info \{1,\}\/var\/log\/.\{1,\}" |wc -l`
if [ "${IS_EXIST}" = "0" ] ; then
echo " " >> /etc/rsyslog.conf
echo "authpriv.info /var/log/${LOGIN_EVENTS_FILE_NAME}" >> /etc/rsyslog.conf
else
logtext "has authpriv.info set, passing..."
fi
# restart the syslog service
#systemctl restart rsyslog
Display --indent 2 --text "- Setting the rsyslog.conf, recording the login events... " --result FINISHED --color GREEN
else
Display --indent 2 --text "- Skip recording login events due to config file... " --result SKIPPING --color YELLOW
fi