File: //opt/BCLinux/bse/secure_set/s20_syslogAuth
#!/bin/sh
#=====================================================================
InsertSection "Recording the auth events..."
if [ $RECORDING_AUTH_EVENTS -eq 1 ]; then
if [ -f /etc/rsyslog.conf ];then
cp -np /etc/rsyslog.conf /etc/rsyslog.conf_bak
fi
if [ -f /etc/syslog.conf ];then
cp -np /etc/syslog.conf /etc/syslog.conf_bak
fi
#--------------recording the auth events--------------
IS_EXIST=`egrep -v '^$|^#' /etc/rsyslog.conf | grep -E '^auth.none' | grep "auth.none \{1,\}\/var\/log\/.\{1,\}" | wc -l`
if [ "${IS_EXIST}" = "0" ] ; then
echo " " >> /etc/rsyslog.conf
echo "auth.none /var/log/${AUTH_EVENTS_FILE_NAME}" >> /etc/rsyslog.conf
else
logtext "has auth.none set, passing..."
fi
# restart the syslog service
#systemctl restart rsyslog
Display --indent 2 --text "- Setting the rsyslog.conf, recording the auth events... " --result FINISHED --color GREEN
else
Display --indent 2 --text "- Skip set password complex due to config file... " --result SKIPPING --color YELLOW
fi