File: //opt/BCLinux/bse/secure_check/c17_syslogLogin
#!/bin/sh
#=======================================================
InsertSection "check if record the user login events"
SYSLOG_CONF="/etc/rsyslog.conf /etc/syslog.conf"
for i in ${SYSLOG_CONF}
do
if [ -s ${i} ];then
cp -np ${i} ${i}_bak
grep "authpriv.info \{1,\}\/var\/log\/.\{1,\}" ${i}|grep -v "#" |wc -l | while read count
do
if [ $count -lt 1 ];then
echo "c17" >> $RESULT_FILE
echo "" >> $RESULT_FILE
logtext "WRN_C17: $(loadtext TXT_WRN_C17)"
logtext "Suggestion: $(loadtext TXT_SUG_C17)"
Display --indent 2 --text "- Check if there have authpriv.info set... " --result WARNING --color RED
AddHP 0 1
else
logtext "The security audit modle authpriv.info is set, checking OK"
Display --indent 2 --text "- Check if there have authpriv.info set... " --result OK --color GREEN
AddHP 1 1
fi
done
fi
done