equal
deleted
inserted
replaced
|
1 format = {host} {msg} |
|
2 |
|
3 [sudo] |
|
4 program = sudo |
|
5 pattern = ^\s*(?P<username>\S+) : TTY=(?P<tty>\S+) ; PWD=(?P<pwd>.+?) ; USER=(?P<target_user>\S+) ; (?:ENV=(?P<env>.+?) ; )?COMMAND=(?P<command>.*) |
|
6 |
|
7 format = {login}:{tty} - {user}@{host}:{pwd} - {command!r} |
|
8 |
|
9 #pattern = \s*(?P<login>\S+) : TTY=(?P<tty>\S+)\s; PWD=(?P<pwd>.+?)\s; USER=(?P<user>\S+)\s;( COMMAND=(?P<command>.*) |
|
10 |
1 [puppet_readshadow] |
11 [puppet_readshadow] |
2 program = sudo |
12 program = sudo |
3 pattern = \s*(?P<login>puppet) : TTY=(?P<tty>\S+)\s; PWD=(?P<pwd>.+?)\s; USER=(?P<user>root)\s; COMMAND=(?P<command>/usr/bin/getent shadow \w+) |
13 pattern = \s*(?P<login>puppet) : TTY=(?P<tty>\S+)\s; PWD=(?P<pwd>.+?)\s; USER=(?P<user>root)\s; COMMAND=(?P<command>/usr/bin/getent shadow \w+) |
4 format = |
14 format = |
5 |
15 |
6 [sudo] |
|
7 program = sudo |
|
8 pattern = \s*(?P<login>\S+) : TTY=(?P<tty>\S+)\s; PWD=(?P<pwd>.+?)\s; USER=(?P<user>\S+)\s; COMMAND=(?P<command>.*) |
|
9 format = {login}:{tty} - {user}@{host}:{pwd} - {command!r} |
|
10 |
|
11 [sudo_env] |
|
12 program = sudo |
|
13 pattern = \s*(?P<login>\S+) : TTY=(?P<tty>\S+) ; PWD=(?P<pwd>.+?) ; USER=(?P<user>\S+) ; ENV=(?P<env>.+?) ; COMMAND=(?P<command>.*) |
|
14 format = {login}:{tty} - {user}@{host}:{pwd} - {env} {command!r} |
|
15 |
16 |
16 [ssh] |
17 [ssh] |
17 program = sshd |
18 program = sshd |
18 pattern = \s*Accepted password for (?P<user>\S+) from (?P<ip>\S+) port (?P<port>\S+) (?P<proto>\S+) |
19 pattern = \s*Accepted password for (?P<user>\S+) from (?P<ip>\S+) port (?P<port>\S+) (?P<proto>\S+) |
19 format = SSH login for {user}@{host} from {ip} |
20 format = SSH login for {user}@{host} from {ip} |
22 program = cron |
23 program = cron |
23 |
24 |
24 [su_nobody] |
25 [su_nobody] |
25 program = su |
26 program = su |
26 pattern = Successful su for nobody by root|\+ \?\?\? root:nobody |
27 pattern = Successful su for nobody by root|\+ \?\?\? root:nobody |
27 #flags = re.IGNORECASE |
|
28 |
28 |
29 [puppet] |
29 [puppet] |
30 program = puppet |
30 program = puppet |
31 format = {host} {msg} |
|
32 |
|
33 [all] |
|
34 format = {host} {msg} |
|