Displaying 20 results from an estimated 20000 matches similar to: "vfs audit logs"
2004 May 11
1
BUG: Vfs audit module & samba 3.0.4 ==> share unacces sible
add to each share
writeable = yes
or
read-only = no
This Helps!
Rauno
-----Original Message-----
From: werner maes [mailto:werner.maes@cc.kuleuven.ac.be]
Sent: 11. mai 2004. a. 16:19
To: samba@samba.org
Subject: [Samba] BUG: Vfs audit module & samba 3.0.4 ==> share unaccessible
Hello
Maybe there's a bug in samba-3.0.4.
The following configuration does NO longer work. It did
2004 May 11
0
BUG: Vfs audit module & samba 3.0.4 ==> share unaccessible
Hello
Maybe there's a bug in samba-3.0.4.
The following configuration does NO longer work. It did work fine in
samba-3.0.2a. I did not test samba-3.0.3
The share is no longer accessible !!!
[BKHI-CC3]
path = /home/BKHI-CC3
valid users = @BKHI-CC3-R, @BKHI-CC3-W
write list = @BKHI-CC3-W
force group = +BKHI-CC3-W
create mask = 0664
2005 Feb 01
1
SLES9 Module '/usr/lib/samba/vfs/audit.so' loaded, Can't find a vfs module [/usr/lib/samba/vfs/audit.so]
Any ideas why a vfs module loads successfully then can't be found?
[2005/01/30 03:52:08, 5] lib/util_seaccess.c:se_access_check(309)
se_access_check: access (2) granted.
[2005/01/30 03:52:08, 3] smbd/vfs.c:vfs_init_default(203)
Initialising default vfs hooks
[2005/01/30 03:52:08, 3] smbd/vfs.c:vfs_init_custom(229)
Initialising custom vfs hooks from [/usr/lib/samba/vfs/audit.so]
2007 Aug 01
1
how to configure vfs object = audit
Dear all, someone can help i have samba and i won to
see activied user, open, closed, delete, rename files
can samba do it?and i know to configured the vfs
object = audit
this is my sample script :
[AnCtest]
comment = Audit and Controlling Tester
vfs object = audit
veto files =
/*.exe/*.mp3/*.msi/*.mpeg/*.mov/*.scr/*.dat/*.wav/*.3gp
delete veto files = yes
nt acl support = yes
2003 May 28
2
vfs modules audit + recycle
hi,
i use samba 2.2.8a
on a share i wanted to use the audit.so and recycle.so modules. in my
smb.conf i added the following share
[dir]
comment = dir
valid users = @edv
writeable = yes
create mode = 777
path = /data/
directory mode = 777
vfs object = /usr/lib/samba/vfs/audit.so
vfs object = /usr/lib/samba/vfs/recycle.so
vfs options = /etc/samba/recycle.conf
with this config the recycle bin is
2005 Nov 09
2
Syslog x Samba VFS audit
Hello all,
Recently I,ve activated the Samba vfs audit module on my CentOS server.
Then, I configured syslog to save the events, how open files, create
directories.. in /var/log/samba/audit.log, but the same information are
being stored in /var/log/messages too..
How I can configure Syslog to store this informations only in messages
log file?
Bellow, a part of my syslog.conf
2006 Feb 16
1
Rejoining Computers to the domain
Hi list
I have a query, I have a samba 3.0.21 with openldap, all my windows clients
are joined to PDC.
but suddenly now , all my windows clients uanble to login
but when i do getent passwd on the server , i could see all my computer
accounts . even
when i do ldapsearch -x -b "ou=Computers,dc=msdpl,dc=com" , i could see the
list of computer account names
but my windows clients report
2004 May 27
1
Problem with VFS audit and recycle
Is there anyone running Samba 3.0.X on Solaris 8 that has VFS working? I
am dying to know if this is a problem with my setup or if there is
something else going on. If you do have it working, please let me know
which module. Thanks.
Bill Knox
Lead Operating Systems Programmer/Analyst
The MITRE Corporation
---------- Forwarded message ----------
Date: Tue, 25 May 2004 13:54:26 -0400
2020 Nov 21
0
Cannot delete (empty) folder from Mac client
Hello.
A Mac client of mine has a problem deleting an empty folder from the
root of a Samba 4.12 server share, reporting a permission issue;
however, the more I look at it, the more I am convinced it should be
able to delete it.
smb.conf:
> [global]
> workgroup=XXXXXXXX
> realm=XXXXXXXX.local
> interfaces=em0
> hosts allow=192.168.XXX. 10.0.XXX.2
2003 Feb 11
1
2.2.7a panic with VFS Audit when writing file (reading is ok)
Running SAMBA 2.2.7a compiled with Audit support, enabled on a share:
[global]
workgroup = HCAT
server string = Samba Server for HCAT
hosts allow = xxx.xxx. yyy.yyy.yyy.
load printers = no
log file = /var/log/log.%m
max log size = 50
security = user
encrypt passwords =
2004 Sep 11
0
Questions on VFS modules (audit)
Hello,
I'm configuring Samba 3.0.6 on Debian stable, after using version 2.2.8a
for a while.
I have some questions on VFS modules, which could be summed up into a
single big question: is there any documentation about them, other than the
few paragaphs in the official howto?
Now for the single questions:
1. audit: its output goes into syslog, no options to change this, right?
And also no
2009 Feb 10
0
[Fwd: Re: dovecot logs to audit.log not to maillog]
Hello,
now I have done this:
under http://wiki.dovecot.org/Logging?highlight=(logging)
Rotating Logs
is the following string
-----------------------
/bin/kill -USR1 `cat /var/run/dovecot/master.pid 2>/dev/null` 2>
/dev/null || true
------------------------
This string I have insert in
/etc/logrotate.d/syslog under the lines:
postrotate
/bin/kill -HUP `cat /var/run/syslogd.pid
2006 Feb 01
2
VFS audit
I would like to turn on auditing for a particular share and have all
auditing go to the username.machinename.log files. If I turn on audit
then no matter which way I configure it, it either goes to just syslog,
or both. My goal is to just log to the samba files and take the wieght
off of syslog. I have searched and searched but can't find but a
solution that works. Any help would be
2018 May 05
2
Samba Audit Logs
Hi,
My apologies if this isn't the right place to ask this question.
We have trying to setup auditing in Samba but can't seem to get it to work.
The audit log file is empty and we see some entries about file/folders in
the /var/log/samba/%m but not the actual audit bits. Can someone please
assist or point in the correct direction?
syslog = 0
log file = /var/log/samba/%m
Log level = 0
2018 May 06
1
Samba Audit Logs
I think the issue is permissions related. I changed the log location to
/tmp/audit.log and now it is populating. What should be the permissions for
/var/log/samba/audit.log?
On Mon, May 7, 2018 at 12:29 AM, Robin G <robinghere3 at gmail.com> wrote:
> Hi Rowland,
>
> Thank you.
>
> I tried both options. The following is using option 2
> [global]
> vfs objects =
2018 May 06
0
Samba Audit Logs
Hi Rowland,
Thank you.
I tried both options. The following is using option 2
[global]
vfs objects = full_audit
[homes]
create mask = 0700
directory mask = 0700
browseable = No
read only = No
path = %H
full_audit:prefix = %u|%I|%S
full_audit:failure = none
full_audit:success = mkdir rmdir read pread write pwrite rename
unlink
2009 Feb 09
2
dovecot logs to audit.log not to maillog
Hello,
I have a curious phenomenon.
Dovecot logs normally to /var/log/maillog.
If I restart my server, dovecot loggs to /var/log/audit/audit.log.
If I restart dovecot, dovecot loggs to /var/log/maillog again.
And I think, wenn logrotate is restarting, dovecot logs to audit.log.
But I don't know why.
Any Ideas?
greetings Ralf
2012 Oct 31
2
samba4: audit logs
hi
I can see some vfs audit module for shares. is there something
compareable for authentications and/or ldap access/modifications?
at least I'd like to see successfull or failed authentications attempts.
with "log level = 2" I can't find these in the logfile.
- Thomas
2004 May 18
1
Problem with VFS audit and recycle (fwd)
This problem continues under 3.0.4 on Solaris 8 - attempting to use the
"vfs object" parameter in a share prevents access to the share and results
in the following in the log files:
[2004/05/10 16:04:57, 0] lib/module.c:do_smb_load_module(57)
Error trying to resolve symbol 'init_module' in
/usr/local/lib/vfs/audit.so: ld.so.1: /usr/local/sbin/smbd: fatal:
2007 Oct 28
1
Interpreting audit logs?
Whenever I review audit logs, it is difficult for me to determine if an
account was logged in at an usual day/time because there is no timestamp
next to any entry, at least as I interpret the format. How, then do I
properly and successfully review the audit log entries based on a
date/time stamp?
Also, how can I filter out root and sudo account entries, displaying
everyone else in audit?