Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
04-linux:10-administration:60-logs-syteme [2015/10/17 00:50] – Roge | 04-linux:10-administration:60-logs-syteme [2017/10/06 23:40] (Version actuelle) – modification externe 127.0.0.1 | ||
---|---|---|---|
Ligne 1: | Ligne 1: | ||
+ | ====== Logs système ====== | ||
+ | |||
+ | ===== Objectif ===== | ||
+ | |||
+ | Cette page présente les logs disponibles sur un système Linux Ubuntu afin de permettre de localiser et d' | ||
+ | |||
+ | ===== Les logs standard ===== | ||
+ | |||
+ | ==== Généralités ==== | ||
+ | |||
+ | Les logs systèmes sont //souvent// stockés dans ''/ | ||
+ | |||
+ | <code bash> | ||
+ | roge@N73SM ~ $ ll /var/log | ||
+ | total 3668 | ||
+ | -rw-r--r-- 1 root root 43807 août 25 19:02 alternatives.log | ||
+ | drwxr-xr-x 2 root root 4096 août 25 17:54 apt | ||
+ | -rw-r--r-- 1 root root 794 juin 24 12:25 aptitude | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-r--r-- 1 root root 6031 août 25 21:26 boot.log | ||
+ | -rw-r--r-- 1 root root 64920 juin 24 11:59 bootstrap.log | ||
+ | -rw-rw---- 1 root utmp 1920 août 26 19:11 btmp | ||
+ | drwxr-xr-x 2 root root 4096 août 25 18:24 ConsoleKit | ||
+ | drwxr-xr-x 2 root root 4096 août 28 02:24 cups | ||
+ | -rw-r----- 1 root adm 74946 août 25 21:26 dmesg | ||
+ | -rw-r----- 1 root adm 79678 août 25 18:24 dmesg.0 | ||
+ | -rw-r----- 1 root adm 59 juin 24 11:58 dmesg.1.gz | ||
+ | -rw-r--r-- 1 root root 1774266 août 26 18:25 dpkg.log | ||
+ | -rw-r--r-- 1 root root 32032 août 25 20:33 faillog | ||
+ | -rw-r--r-- 1 root root 3442 août 25 18:59 fontconfig.log | ||
+ | drwxr-xr-x 2 root root 4096 juin 24 11:58 fsck | ||
+ | -rw-r--r-- 1 root root 1358 août 26 18:10 gpu-manager.log | ||
+ | drwxr-xr-x 3 root root 4096 juin 24 12:10 hp | ||
+ | drwxr-xr-x 2 root root 4096 août 25 17:54 installer | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-rw-r-- 1 root utmp 292292 août 28 23:06 lastlog | ||
+ | drwxr-xr-x 2 root root 4096 août 26 18:10 mdm | ||
+ | -rw-r--r-- 1 root root 5658 août 25 21:26 mintsystem.log | ||
+ | -rw-r--r-- 1 root root 55 août 25 21:26 nvidia-prime-upstart.log | ||
+ | -rw-r--r-- 1 root root 83194 août 28 22:18 pm-powersave.log | ||
+ | -rw-r--r-- 1 root root 146330 août 28 22:18 pm-suspend.log | ||
+ | -rw-r--r-- 1 root root 20 août 26 18:10 prime-supported.log | ||
+ | -rw-r--r-- 1 root root 0 juin 24 12:16 pycentral.log | ||
+ | drwxr-xr-x 3 root root 4096 août 25 18:26 samba | ||
+ | drwx------ 2 speech-dispatcher root 4096 févr. 19 2014 speech-dispatcher | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-r----- 1 syslog | ||
+ | -rw-r--r-- 1 root root 366081 août 25 21:26 udev | ||
+ | drwxr-xr-x 2 root root 4096 août 25 21:25 unattended-upgrades | ||
+ | drwxr-xr-x 2 root root 4096 août 27 09:15 upstart | ||
+ | -rw-r--r-- 1 root root 1303 août 26 18:24 vbox-install.log | ||
+ | -rw-rw-r-- 1 root utmp 26880 août 28 23:06 wtmp | ||
+ | -rw-r--r-- 1 root root 68084 août 28 22:57 Xorg.0.log | ||
+ | -rw-r--r-- 1 root root 43097 août 25 21:25 Xorg.0.log.old | ||
+ | -rw-r--r-- 1 root root 28284 août 26 18:11 Xorg.20.log | ||
+ | roge@N73SM ~ $ | ||
+ | </ | ||
+ | |||
+ | Voir aussi [[http:// | ||
+ | |||
+ | ==== auth.log ==== | ||
+ | |||
+ | Ce fichier enregistre les authentifications. | ||
+ | |||
+ | <code bash> | ||
+ | roge@N73SM ~ $ cat / | ||
+ | Aug 25 18:24:01 N73SM systemd-logind[865]: | ||
+ | Aug 25 18:24:14 N73SM mdm[1493]: pam_unix(mdm-autologin: | ||
+ | Aug 25 18:24:14 N73SM systemd-logind[865]: | ||
+ | Aug 25 18:24:14 N73SM systemd-logind[865]: | ||
+ | Aug 25 18:24:14 N73SM mdm[1493]: pam_ck_connector(mdm-autologin: | ||
+ | Aug 25 18:24:23 N73SM polkitd(authority=local): | ||
+ | ...... | ||
+ | Aug 25 18:32:22 N73SM sudo: roge : TTY=pts/2 ; PWD=/ | ||
+ | Aug 25 18:32:22 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 18:32:22 N73SM sudo: pam_unix(sudo: | ||
+ | ..... | ||
+ | Aug 25 18:42:08 N73SM pkexec[6186]: | ||
+ | ...... | ||
+ | Aug 25 21:22:08 N73SM cinnamon-screensaver-dialog: | ||
+ | Aug 25 21:22:38 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:22:38 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:22:38 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:22:38 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:22:43 N73SM sudo: roge : TTY=unknown ; PWD=/ | ||
+ | Aug 25 21:22:43 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:23:54 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:24:44 N73SM sudo: roge : TTY=unknown ; PWD=/ | ||
+ | Aug 25 21:24:44 N73SM sudo: pam_unix(sudo: | ||
+ | Aug 25 21:24:57 N73SM nxexec: pam_unix(nx: | ||
+ | Aug 25 21:24:57 N73SM nxexec: pam_ck_connector(nx: | ||
+ | Aug 25 21:24:57 N73SM nxexec: pam_unix(nx: | ||
+ | Aug 25 21:24:58 N73SM sudo: pam_unix(sudo: | ||
+ | .... | ||
+ | Aug 25 21:26:16 N73SM sshd[1289]: Server listening on 0.0.0.0 port xxxxx. | ||
+ | Aug 25 21:26:16 N73SM sshd[1289]: Server listening on :: port xxxxx. | ||
+ | .... | ||
+ | Aug 25 21:26:26 N73SM mdm[1685]: pam_unix(mdm-autologin: | ||
+ | Aug 25 21:26:26 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:26:26 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:26:26 N73SM mdm[1685]: pam_ck_connector(mdm-autologin: | ||
+ | Aug 25 21:26:37 N73SM polkitd(authority=local): | ||
+ | Aug 25 21:26:58 N73SM nxexec: pam_unix(nx: | ||
+ | ..... | ||
+ | Aug 25 21:44:49 N73SM sshd[4662]: Accepted publickey for roge from 192.168.xxx.xxx port xxxxx ssh2: RSA xx: | ||
+ | Aug 25 21:44:49 N73SM sshd[4662]: pam_unix(sshd: | ||
+ | Aug 25 21:44:49 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:44:49 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:44:49 N73SM sshd[4673]: Received disconnect from 192.168.xxx.xxx: | ||
+ | Aug 25 21:44:49 N73SM sshd[4662]: pam_unix(sshd: | ||
+ | ..... | ||
+ | Aug 25 21:58:37 N73SM sshd[10835]: | ||
+ | Aug 25 21:58:37 N73SM sshd[10835]: | ||
+ | Aug 25 21:58:37 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:58:37 N73SM systemd-logind[930]: | ||
+ | Aug 25 21:58:37 N73SM sshd[10846]: | ||
+ | Aug 25 21:58:37 N73SM sshd[10835]: | ||
+ | .....</ | ||
+ | |||
+ | ==== boot.log ==== | ||
+ | |||
+ | Affiche la séquence de démarrage sysème. | ||
+ | |||
+ | <code bash> | ||
+ | roge@N73SM ~ $ cat / | ||
+ | * Stopping adjust system clock and timezone | ||
+ | * Starting Mount filesystems on boot [ OK ] | ||
+ | * Starting Fix-up sensitive /proc filesystem entries | ||
+ | * Starting Populate /dev filesystem | ||
+ | * Starting Populate and link to /run filesystem | ||
+ | * Stopping Fix-up sensitive /proc filesystem entries | ||
+ | * Stopping Populate /dev filesystem | ||
+ | * Stopping Populate and link to /run filesystem | ||
+ | * Stopping Track if upstart is running in a container | ||
+ | * Starting Initialize or finalize resolvconf | ||
+ | * Starting set console keymap | ||
+ | * Starting Signal sysvinit that virtual filesystems are mounted | ||
+ | * Starting Signal sysvinit that virtual filesystems are mounted | ||
+ | * Starting set sysctls from / | ||
+ | * Starting Bridge udev events into upstart | ||
+ | * Starting Signal sysvinit that remote filesystems are mounted | ||
+ | * Stopping set console keymap | ||
+ | * Stopping set sysctls from / | ||
+ | * Starting device node and kernel event manager | ||
+ | * Starting load modules from / | ||
+ | * Starting cold plug devices | ||
+ | * Starting log initial device creation | ||
+ | * Stopping load modules from / | ||
+ | * Starting load fallback graphics devices | ||
+ | * Stopping load fallback graphics devices | ||
+ | * Starting configure network device security | ||
+ | * Starting Signal sysvinit that the rootfs is mounted | ||
+ | * Starting configure network device security | ||
+ | * Starting Uncomplicated firewall | ||
+ | * Starting Mount network filesystems | ||
+ | * Starting Clean /tmp directory | ||
+ | * Stopping Mount network filesystems | ||
+ | * Starting configure network device | ||
+ | * Stopping Read required files in advance (for other mountpoints) | ||
+ | * Starting Bridge socket events into upstart | ||
+ | * Starting configure network device security | ||
+ | * Starting configure network device | ||
+ | * Starting configure network device | ||
+ | * Stopping Read required files in advance (for other mountpoints) | ||
+ | * Stopping Read required files in advance (for other mountpoints) | ||
+ | * Stopping Clean /tmp directory | ||
+ | * Starting Signal sysvinit that local filesystems are mounted | ||
+ | * Starting restore software rfkill state [ OK ] | ||
+ | * Starting SMB/CIFS File Server | ||
+ | * Stopping restore software rfkill state [ OK ] | ||
+ | * Starting flush early job output to logs [ OK ] | ||
+ | * Stopping Failsafe Boot Delay [ OK ] | ||
+ | * Starting Enabling additional executable binary formats | ||
+ | * Stopping Mount filesystems on boot [ OK ] | ||
+ | * Starting System V initialisation compatibility | ||
+ | * Stopping flush early job output to logs [ OK ] | ||
+ | * Starting Bridge file events into upstart | ||
+ | * VirtualBox Additions disabled, not in a Virtual Machine | ||
+ | * Starting system logging daemon | ||
+ | * Setting sensors limits | ||
+ | * Starting D-Bus system message bus [ OK ] | ||
+ | * Starting modem connection manager | ||
+ | * Starting configure network device security | ||
+ | * Starting mDNS/DNS-SD daemon | ||
+ | * Starting Reload cups, upon starting avahi-daemon to make sure remote queues are populated | ||
+ | * Stopping Reload cups, upon starting avahi-daemon to make sure remote queues are populated | ||
+ | * Starting SystemD login management service | ||
+ | * Starting bluetooth daemon | ||
+ | * Starting network connection manager | ||
+ | * Stopping cold plug devices | ||
+ | * Stopping log initial device creation | ||
+ | * Starting configure network device security | ||
+ | * Starting enable remaining boot-time encrypted block devices | ||
+ | * Starting save udev log and update rules [ OK ] | ||
+ | * Stopping save udev log and update rules [ OK ] | ||
+ | * Starting configure virtual network devices | ||
+ | * Starting SMB/CIFS File and Active Directory Server | ||
+ | * Starting SMB/CIFS File and Active Directory Server | ||
+ | * Setting up X socket directories... | ||
+ | * Stopping System V initialisation compatibility | ||
+ | * Starting System V runlevel compatibility | ||
+ | * Starting Restore Sound Card State [ OK ] | ||
+ | * Starting save kernel messages | ||
+ | * Starting NVIDIA PRIME Power Saving Mode [ OK ] | ||
+ | * Starting anac(h)ronistic cron [ OK ] | ||
+ | * Starting ACPI daemon | ||
+ | * Stopping Restore Sound Card State [ OK ] | ||
+ | * Loading cpufreq kernel modules... | ||
+ | * CPU0... | ||
+ | * Starting regular background program processing daemon | ||
+ | * Stopping Restore Sound Card State [ OK ] | ||
+ | * Stopping save kernel messages | ||
+ | * Stopping anac(h)ronistic cron [ OK ] | ||
+ | * CPU1... | ||
+ | * Starting CPU interrupts balancing daemon | ||
+ | * Starting OpenSSH server | ||
+ | * speech-dispatcher disabled; edit / | ||
+ | * VirtualBox Additions disabled, not in a Virtual Machine | ||
+ | saned disabled; edit / | ||
+ | * Starting MDM Display Manager | ||
+ | * Stopping Send an event to indicate plymouth is up [ OK ] | ||
+ | * Restoring resolver state... | ||
+ | * Starting Mount network filesystems | ||
+ | * Stopping Mount network filesystems | ||
+ | * Starting NetBIOS name server | ||
+ | roge@N73SM ~ $ | ||
+ | </ | ||
+ | |||
+ | <fs x-large>< | ||
+ | |||
+ | ===== Documentation ===== | ||
+ | |||
+ | [[https:// | ||
+ | |||