Ubuntu 14.04服务器auth.log为空,如何获取SSH密钥登录日志?
Let’s walk through this step by step—Ubuntu 14.04 uses rsyslog for logging, so there are a few common culprits here, plus ways to ensure you capture all SSH key-related activity.
1. First, Check if rsyslog is Running
If the rsyslog daemon isn’t active, no logs will be written to /var/log/auth.log at all. Run this to verify:
sudo service rsyslog status
If it shows "stopped", start it immediately:
sudo service rsyslog start
And make sure it starts on boot:
sudo update-rc.d rsyslog defaults
2. Verify SSHD’s Logging Configuration
SSHD might not be configured to send logs to the AUTH facility (which feeds into auth.log). Open the SSH config file:
sudo nano /etc/ssh/sshd_config
Look for these two lines—they should be set like this (uncomment them if they’re commented out):
SyslogFacility AUTHPRIV LogLevel VERBOSE
AUTHPRIVensures logs go toauth.log(more secure than plain AUTH, as it restricts access to admins)VERBOSEwill log detailed info about SSH key attempts, including key fingerprints and source IPs (critical for your goal of tracking all login attempts)
Save the file and restart SSHD to apply changes:
sudo service ssh restart
3. Check Alternative Log Locations
If auth.log is still empty, check these spots:
/var/log/syslog: Sometimes rsyslog routes SSH logs here instead ofauth.log—filter for SSH activity with:grep sshd /var/log/syslog- Archived log files: Ubuntu rotates logs regularly, so old SSH logs might be in compressed files like
auth.log.1,auth.log.2.gz, etc. View them with:# For uncompressed files cat /var/log/auth.log.1 | grep sshd # For compressed files zcat /var/log/auth.log.*.gz | grep sshd
4. Fix Log File Permissions
If rsyslog can’t write to auth.log due to incorrect permissions, logs will fail to populate. Check the permissions:
ls -l /var/log/auth.log
It should show permissions rw-r----- (640) and owned by root:adm. If not, fix them:
sudo chmod 640 /var/log/auth.log sudo chown root:adm /var/log/auth.log
Then restart rsyslog to pick up the changes.
5. Add Extra Monitoring with Auditd (Optional but Powerful)
For even more granular tracking of SSH activity (including post-login commands if needed), install auditd:
sudo apt-get install auditd
Add a rule to monitor SSHD executions:
sudo auditctl -w /usr/sbin/sshd -p x -k sshd_activity
You can then query audit logs for SSH-related events with:
ausearch -k sshd_activity
This will capture not just login attempts, but also when SSHD starts/stops, which can be useful for debugging.
Once you’ve gone through these steps, you should start seeing SSH key login attempts (both successful and failed) in /var/log/auth.log. If you’re still not seeing anything, try initiating a test SSH key login from another machine—this should trigger a log entry that you can check.
内容的提问来源于stack exchange,提问作者praiseHellRaiseDale

