I am learning Debian on RaspberryPI.
I've installed 'logwatch' and 'fail2ban' recently and those two were working Great!
A few days ago I've spotted that I don't have a file "auth.log" but I do have "auth.log.gz1" etc. (so archive data)
I've used command:
touch auth.log
to create this file, than
chown root:adm
to change its premissions.
However this file is still not working - I can't see any entry in to for the last 2 days even if I was loging in trough SSH.
Can you advise:
1. why this file is gone? where to look for a reasons?
2. how to fix the issue, so all my SSH connections (and attacks) will be recorded?
PS.
pi@pi ~ $ uname -a
Linux pi.local 3.10.25+ #622 PREEMPT Fri Jan 3 18:41:00 GMT 2014 armv6l GNU/Linux
Asked by Adam
(381 rep)
Jan 7, 2014, 04:40 PM
Last activity: Jun 22, 2025, 08:31 PM
Last activity: Jun 22, 2025, 08:31 PM