You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 14.04服务器auth.log为空,如何获取SSH密钥登录日志?

Troubleshooting Empty /var/log/auth.log & Capturing SSH Key Login Activity on Ubuntu 14.04

Let’s walk through this step by step—Ubuntu 14.04 uses rsyslog for logging, so there are a few common culprits here, plus ways to ensure you capture all SSH key-related activity.

1. First, Check if rsyslog is Running

If the rsyslog daemon isn’t active, no logs will be written to /var/log/auth.log at all. Run this to verify:

sudo service rsyslog status

If it shows "stopped", start it immediately:

sudo service rsyslog start

And make sure it starts on boot:

sudo update-rc.d rsyslog defaults

2. Verify SSHD’s Logging Configuration

SSHD might not be configured to send logs to the AUTH facility (which feeds into auth.log). Open the SSH config file:

sudo nano /etc/ssh/sshd_config

Look for these two lines—they should be set like this (uncomment them if they’re commented out):

SyslogFacility AUTHPRIV
LogLevel VERBOSE
  • AUTHPRIV ensures logs go to auth.log (more secure than plain AUTH, as it restricts access to admins)
  • VERBOSE will log detailed info about SSH key attempts, including key fingerprints and source IPs (critical for your goal of tracking all login attempts)

Save the file and restart SSHD to apply changes:

sudo service ssh restart

3. Check Alternative Log Locations

If auth.log is still empty, check these spots:

  • /var/log/syslog: Sometimes rsyslog routes SSH logs here instead of auth.log—filter for SSH activity with:
    grep sshd /var/log/syslog
    
  • Archived log files: Ubuntu rotates logs regularly, so old SSH logs might be in compressed files like auth.log.1, auth.log.2.gz, etc. View them with:
    # For uncompressed files
    cat /var/log/auth.log.1 | grep sshd
    # For compressed files
    zcat /var/log/auth.log.*.gz | grep sshd
    

4. Fix Log File Permissions

If rsyslog can’t write to auth.log due to incorrect permissions, logs will fail to populate. Check the permissions:

ls -l /var/log/auth.log

It should show permissions rw-r----- (640) and owned by root:adm. If not, fix them:

sudo chmod 640 /var/log/auth.log
sudo chown root:adm /var/log/auth.log

Then restart rsyslog to pick up the changes.

5. Add Extra Monitoring with Auditd (Optional but Powerful)

For even more granular tracking of SSH activity (including post-login commands if needed), install auditd:

sudo apt-get install auditd

Add a rule to monitor SSHD executions:

sudo auditctl -w /usr/sbin/sshd -p x -k sshd_activity

You can then query audit logs for SSH-related events with:

ausearch -k sshd_activity

This will capture not just login attempts, but also when SSHD starts/stops, which can be useful for debugging.

Once you’ve gone through these steps, you should start seeing SSH key login attempts (both successful and failed) in /var/log/auth.log. If you’re still not seeing anything, try initiating a test SSH key login from another machine—this should trigger a log entry that you can check.

内容的提问来源于stack exchange,提问作者praiseHellRaiseDale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:20:41