Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Save computerquip/d9e3841518fee93dfb01ee1f951438e8 to your computer and use it in GitHub Desktop.
Save computerquip/d9e3841518fee93dfb01ee1f951438e8 to your computer and use it in GitHub Desktop.
Mar 01 12:31:35 zagreus.realm.example.com sshd-session[2052]: pam_sss(sshd:auth): authentication success; logname= uid=0 euid=0 tty=ssh ruser= rhost=<snip> [email protected]
Mar 01 12:31:35 zagreus.realm.example.com audit[2052]: USER_AUTH pid=2052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:authentication grantors=pam_usertype,pam_usertype,pam_sss acct="[email protected]" exe="/usr/libexec/openssh/sshd-session" hostname=<snip> addr=<snip> terminal=ssh res=success'
Mar 01 12:31:36 zagreus.realm.example.com audit[2052]: USER_ACCT pid=2052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_unix,pam_sss,pam_permit acct="[email protected]" exe="/usr/libexec/openssh/sshd-session" hostname=<snip> addr=<snip> terminal=ssh res=success'
Mar 01 12:31:36 zagreus.realm.example.com sshd-session[2049]: Accepted keyboard-interactive/pam for [email protected] from <snip> port 63131 ssh2
Mar 01 12:31:36 zagreus.realm.example.com audit[2049]: CRYPTO_KEY_USER pid=2049 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2050 suid=74 rport=63131 laddr=<snip> lport=22 exe="/usr/libexec/openssh/sshd-session" hostname=? addr=<snip> terminal=? res=success'
Mar 01 12:31:36 zagreus.realm.example.com audit[2049]: CRED_ACQ pid=2049 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_env,pam_localuser,pam_unix acct="[email protected]" exe="/usr/libexec/openssh/sshd-session" hostname=<snip> addr=<snip> terminal=ssh res=success'
Mar 01 12:31:36 zagreus.realm.example.com audit[2049]: USER_ROLE_CHANGE pid=2049 uid=0 auid=1581400000 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pam_selinux default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/libexec/openssh/sshd-session" hostname=<snip> addr=<snip> terminal=ssh res=success'
Mar 01 12:31:36 zagreus.realm.example.com sshd-session[2049]: pam_systemd(sshd:session): pam-systemd initializing
Mar 01 12:31:36 zagreus.realm.example.com sshd-session[2049]: pam_systemd(sshd:session): Failed to get user record: No such process
Mar 01 12:31:36 zagreus.realm.example.com sshd-session[2049]: pam_unix(sshd:session): session opened for user [email protected](uid=1581400000) by [email protected](uid=0)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment