<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic /var/log/secure flurry of logs in secure.log (how to stop/investigate) in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814001#M24414</link>
    <description>&lt;P&gt;secure log is being populated every minute like this:&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:23 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:23 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: Accepted keyboard-interactive/pam for sas from 10.36.65.178 port 59682 ssh2&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: pam_tty_audit(sshd:session): changed status from 0 to 0&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: pam_unix(sshd:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:53 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:53 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:56 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:56 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:02:26 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:02:26 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:02:29 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:02:29 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;&lt;BR /&gt;how do I stop these or investigate the cause of this,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have checked crond for sas and root user and have not found much here,&amp;nbsp;&lt;/P&gt;&lt;P&gt;also /etc/cron.d/ has just hourly and monthly jobs that should not be populating secure log on such high frequency,&amp;nbsp;&lt;/P&gt;&lt;P&gt;please any ideas why this log is being populated so frequently and it is just wasting space with this consistent log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br, HS&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 07:34:31 GMT</pubDate>
    <dc:creator>reefermadness26</dc:creator>
    <dc:date>2022-05-18T07:34:31Z</dc:date>
    <item>
      <title>/var/log/secure flurry of logs in secure.log (how to stop/investigate)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814001#M24414</link>
      <description>&lt;P&gt;secure log is being populated every minute like this:&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:23 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:23 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: Accepted keyboard-interactive/pam for sas from 10.36.65.178 port 59682 ssh2&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: pam_tty_audit(sshd:session): changed status from 0 to 0&lt;BR /&gt;May 18 10:01:47 sasoa01p sshd[76487]: pam_unix(sshd:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:53 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:53 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:54 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:56 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:56 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:02:26 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:02:26 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:02:27 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:02:29 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:02:29 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;&lt;BR /&gt;how do I stop these or investigate the cause of this,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have checked crond for sas and root user and have not found much here,&amp;nbsp;&lt;/P&gt;&lt;P&gt;also /etc/cron.d/ has just hourly and monthly jobs that should not be populating secure log on such high frequency,&amp;nbsp;&lt;/P&gt;&lt;P&gt;please any ideas why this log is being populated so frequently and it is just wasting space with this consistent log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br, HS&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 07:34:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814001#M24414</guid>
      <dc:creator>reefermadness26</dc:creator>
      <dc:date>2022-05-18T07:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/secure flurry of logs in secure.log (how to stop/investigate)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814162#M24421</link>
      <description>This seems to translate as the root user running the su command to become the user "sas", auditing being turned off (presumably because it's only turned on for root), then the session ends and auditing is turned on again.&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_unix(su:session): session opened for user sas by (uid=0)&lt;BR /&gt;May 18 10:01:20 sasoa01p su: pam_tty_audit(su:session): changed status from 1 to 0&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_unix(su:session): session closed for user sas&lt;BR /&gt;May 18 10:01:21 sasoa01p su: pam_tty_audit(su:session): restored status to 1&lt;BR /&gt;&lt;BR /&gt;Might be worth checking to see what processes are running as the root user, and/or the audit report (aureport --tty)&lt;BR /&gt;&lt;A href="https://linux.die.net/man/8/pam_tty_audit" target="_blank"&gt;https://linux.die.net/man/8/pam_tty_audit&lt;/A&gt;</description>
      <pubDate>Wed, 18 May 2022 19:21:23 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814162#M24421</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2022-05-18T19:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/secure flurry of logs in secure.log (how to stop/investigate)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814242#M24428</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/78975"&gt;@gwootton&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi,&amp;nbsp;&lt;BR /&gt;I have checked aureport -tty documentation link you sent.&lt;BR /&gt;So if auditing is only enabled for root user, would it help if I enable auditing for sas user as well?&lt;/P&gt;&lt;P&gt;then this flurry of logs might stop.&lt;BR /&gt;But I am unable to find pam.conf in my installation, and seems like contents of /etc/pam.d/ are alternatives to that, but I am not sure where I can enable that option so that sas auditing enable flag can be changed.&lt;BR /&gt;then these checks on session auditing might stop in secure log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Br,&amp;nbsp;&lt;/P&gt;&lt;P&gt;HS&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:07:50 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814242#M24428</guid>
      <dc:creator>reefermadness26</dc:creator>
      <dc:date>2022-05-19T09:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/secure flurry of logs in secure.log (how to stop/investigate)</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814317#M24434</link>
      <description>Enabling audit for the sas user might prevent two of those lines from showing up (those for pam_tty_audit) because the status wouldn't be changing, but it would not change what is happening (su being run as root to switch to sas and perform some action or no action). The existing audit report might have some detail on what root is doing when switching to sas. Adding sas to the audit will probably increase other file usage as it will now start capturing sas tty activity as well as root.&lt;BR /&gt;&lt;BR /&gt;The /etc/pam.d/su file is what is being used, and it probably has a session line that is calling some other pam.d file like system-auth where the pam_tty_audit line is. You could do something like grep tty /etc/pam.d/* to find it and make changes.</description>
      <pubDate>Thu, 19 May 2022 15:46:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/var-log-secure-flurry-of-logs-in-secure-log-how-to-stop/m-p/814317#M24434</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2022-05-19T15:46:36Z</dc:date>
    </item>
  </channel>
</rss>

