J-L Boers wrote:

> someone logged on as root. Now I believe that syslog ksyslogd can be
> configured to have these messages tracked and emailed to a specified email
> account. I would also like to log and be alerted to ssh connections, failed

        One way to do this is to download and install the logcheck RPM from
rpmfind.net.  It'll scan your system log every hour and mail you the
results.  It's configurable, so you can give it things to
include/exclude.

> and successful. My question is how and where do i go to tweak something? I'm

        Umm...  "something" like what?  This question is way too broad to
answer, but most system configuration stuff is in /etc (though most of
the stuff in there is templated through the e-smith templates system).

--
Dan Brown, KE6MKS, [EMAIL PROTECTED]
"Meddle not in the affairs of dragons, for you are crunchy
and taste good with ketchup."

Reply via email to