sshd notification no ip

General discussions here

Moderator: rgerhards

sshd notification no ip

Postby tnk » Thu Aug 24, 2006 11:33 am

In syslog you have lines like this:

Aug 23 13:21:19 stagshoot01 sshd[15151]: Accepted keyboard-interactive/pam for root from ::ffff:192.168.100.235 port 53939 ssh2
Aug 23 13:21:19 stagshoot01 sshd[15154]: (pam_unix) session opened for user root by root(uid=0)

In rsyslog you have lines like this:
12:17:01 4 INFO SL stagshoot01 (pam_unix) session opened for user root by (uid=0)
12:17:01 9 INFO SL stagshoot01 (root) CMD ( run-parts --report /etc/cron.hourly)
12:17:01 4 INFO SL stagshoot01 (pam_unix) session closed for user root

How come i don't get the remote host in rsyslog?
tnk
New
 
Posts: 7
Joined: Wed Aug 23, 2006 4:08 pm

Professional Services Information

  • Custom written rsyslog.conf?
  • Maintenance Contract?
  • Installation support?

RE: sshd notification no ip

Postby tnk » Thu Aug 24, 2006 11:34 am

The rsyslog.conf is really simple:

*.* > 192.168.1.10,dbname,username,password
tnk
New
 
Posts: 7
Joined: Wed Aug 23, 2006 4:08 pm

RE: sshd notification no ip

Postby mmeckelein » Thu Aug 24, 2006 11:45 am

Not sure if I got the point. Did you mean the message is

Accepted keyboard-interactive/pam for root from ::ffff:192.168.100.235 port 53939 ssh2


is missing if you are using rsyslog for loggging instead of syslogd?

Michael
mmeckelein
Adiscon Support
 
Posts: 176
Joined: Wed Mar 12, 2003 12:07 pm

Re: RE: sshd notification no ip

Postby Trellian » Sat Jan 20, 2007 1:06 am

mmeckelein wrote:Not sure if I got the point. Did you mean the message is

Accepted keyboard-interactive/pam for root from ::ffff:192.168.100.235 port 53939 ssh2


is missing if you are using rsyslog for loggging instead of syslogd?

Michael


I can confirm this bug. The exact same thing is happening to me. The line beginning with "Accepter keyboard-..." is missing when using rsyslog.

version info:

rsyslogd 1.13.0, compiled with:
FEATURE_PTHREADS (dual-threading)
FEATURE_REGEXP
FEATURE_DB
FEATURE_LARGEFILE
FEATURE_NETZIP (syslog message compression)
SYSLOG_INET (Internet/remote support)
Trellian
New
 
Posts: 6
Joined: Sat Jan 20, 2007 1:04 am

RE: Re: RE: sshd notification no ip

Postby rgerhards » Tue Jan 30, 2007 11:53 am

Somehow I seem to have overlooked this post (and probably some others...).

Could you run rsyslog in debug mode (-d -n interactively) while such a message arrives? If possible, it would also be useful if you could use the DEBUG template.

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 2647
Joined: Thu Feb 13, 2003 11:57 am

RE: Re: RE: sshd notification no ip

Postby Trellian » Tue Jan 30, 2007 1:35 pm

I'll see what I can do. Don't expect me to answer any time soon though.
I'm going ski-ing for two week on wednesday ;)
I'll do some debugging after I get back.
Trellian
New
 
Posts: 6
Joined: Sat Jan 20, 2007 1:04 am

RE: Re: RE: sshd notification no ip

Postby rgerhards » Tue Jan 30, 2007 1:40 pm

Happy skiing :D
User avatar
rgerhards
Site Admin
 
Posts: 2647
Joined: Thu Feb 13, 2003 11:57 am

Google Ads



Return to General

Who is online

Users browsing this forum: No registered users and 0 guests

cron