如果你想拥有你从未拥有过的东西,那么你必须去做你从未做过的事情
麒麟操作系统中的配置文件
一、/etc目录下的配置文件
1、网卡配置文件
网卡配置文件和contos系统类似都在/etc/sysconfig/network-scripts/目录下
[root@localhost ~]#cat /etc/sysconfig/network-scripts/ifcfg-ens33
TYPE=Ethernet # 网络类型 以太网
PROXY_METHOD=none # 配置IP地址的方式 dhcp(自动获取IP地址 家里,改为none)
NAME=ens33 #网卡在系统中显示的名称
DEVICE=ens33 #硬件的名称
ONBOOT=yes #开机自动运行networkMangager服务(网卡自动连接)
IPADDR=10.0.0.8 #IP地址 逻辑地址局域网内唯一 虚拟机和虚拟机不能相同
PREFIX=24 #子网掩码 24 决定了局域网内可以用的IP地址数量10.0.0.1-10.0.0.254
GATEWAY=10.0.0.2 # 网关 去往不同网段的必经之路 去互联网的必经之路(局域网|公网)
DNS1=223.5.5.5 # DNS域名解析服务器
# 公用的DNS服务器地址 223.5.5.5 阿里云
# 114.114.114.114 电信 8.8.8.8 谷歌 202.106.0.20 联通
[root@localhost ~]#
2、本地DNS解析文件(本地域名解析服务)
[root@localhost ~]#cat /etc/hosts
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
WINDOWS的hosts文件地址:
C:\Windows\System32\drivers\etc
3、存放主机名的文件
[root@yunzhongziedu ~]# cat /etc/hostname
yunzhongziedu
一).查看主机名称:
1.命令提示符查看
2.使用命令hostbane回车
3.查看系统命令配置文件 /etc/hostname
[root@yunzhongziedu ~]# hostname
yunzhongziedu
二).修改主机名称的方法
1.临时修改主机名称,重启系统失效
[root@yunzhongziedu ~]# hostname web01
2.重连xshell
注:开机的时候系统会读取/etc/hostname里面是什么,主机名称就是什么
三》 永久修改:
1.直接修改配置文件并重启操作系统
[root@yunzhongziedu ~]# vim /etc/hostname
2.临时+永久让主机名生效 *重点掌握*
[root@yunzhongziedu ~]# hostnamectl set-hostname db01
[root@yunzhongziedu ~]# cat /etc/hostname
db01
四》主机名称重点:
1。查看主机名称
hostname
2.修改主机名称
hostname 主机名称 临时修改 重启系统生效
vim /etc/hostname
hostnamectl set-hostname 主机名称 永久+临时
可以根据你的需要或者服务器跑的服务设置主机名
4、存放DNS配置的文件
[root@localhost ~]#cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 223.5.5.5
/etc/resolv.conf
作用:存放DNS配置的位置。DNS配置文件 配置后直接生效
vim /etc/resolv.conf
nameserver 223.5.5.5
nameserver 114.114.114.11
安装:nslookup命令
[root@yunzhongziedu ~]# yum -y install bind-utils
[root@yunzhongziedu ~]# nslookup www.baidu.com
Server: 223.5.5.5
Address: 223.5.5.5#53
Non-authoritative answer:
www.baidu.com canonical name = www.a.shifen.com.
Name: www.a.shifen.com
Address: 110.242.68.4
Name: www.a.shifen.com
Address: 110.242.68.3
网卡配置和resolv.conf关联
1如果网卡中配置了dns,重启系统网卡会覆盖resoiv.conf
2如果网卡中没配置dns,重启系统网卡不会覆盖resoiv.conf
5、存放环境变量的文件
[root@localhost ~]#cat /etc/profile
# /etc/profile
# System wide environment and startup programs, for login setup
# Functions and aliases go in /etc/bashrc
# It's NOT a good idea to change this file unless you know what you
# are doing. It's much better to create a custom.sh shell script in
# /etc/profile.d/ to make custom changes to your environment, as this
# will prevent the need for merging in future updates.
pathmunge () {
case ":${PATH}:" in
*:"$1":*)
;;
*)
if [ "$2" = "after" ] ; then
PATH=$PATH:$1
else
PATH=$1:$PATH
fi
esac
}
if [ -x /usr/bin/id ]; then
if [ -z "$EUID" ]; then
# ksh workaround
EUID=`/usr/bin/id -u`
UID=`/usr/bin/id -ru`
fi
USER="`/usr/bin/id -un`"
LOGNAME=$USER
MAIL="/var/spool/mail/$USER"
fi
# Path manipulation
if [ "$EUID" = "0" ]; then
pathmunge /usr/sbin
pathmunge /usr/local/sbin
else
pathmunge /usr/local/sbin after
pathmunge /usr/sbin after
fi
HOSTNAME=`/usr/bin/hostnamectl --transient 2>/dev/null`
HISTSIZE=1000
if [ "$HISTCONTROL" = "ignorespace" ] ; then
export HISTCONTROL=ignoreboth
else
export HISTCONTROL=ignoredups
fi
export PATH USER LOGNAME MAIL HOSTNAME HISTSIZE HISTCONTROL
for i in /etc/profile.d/*.sh /etc/profile.d/sh.local ; do
if [ -r "$i" ]; then
if [ "${-#*i}" != "$-" ]; then
. "$i"
else
. "$i" >/dev/null
fi
fi
done
unset i
unset -f pathmunge
if [ -n "${BASH_VERSION-}" ] ; then
if [ -f /etc/bashrc ] ; then
# Bash login shells run only /etc/profile
# Bash non-login shells run only /etc/bashrc
# Check for double sourcing is done in /etc/bashrc.
. /etc/bashrc
fi
fi
export PS1="[\[\e[34;1m\]\u@\[\e[0m\]\[\e[32;1m\]\h\[\e[0m\]\[\e[31;1m\] \W\[\e[0m\]]\\$"
[root@localhost ~]#
6、开机自动挂载的文件
[root@localhost ~]#cat /etc/fstab
#
# /etc/fstab
# Created by anaconda on Wed Nov 13 17:42:30 2024
#
# Accessible filesystems, by reference, are maintained under '/dev/disk/'.
# See man pages fstab(5), findfs(8), mount(8) and/or blkid(8) for more info.
#
# After editing this file, run 'systemctl daemon-reload' to update systemd
# units generated from this file.
#
/dev/mapper/klas-root / xfs defaults 0 0
UUID=4c3bc84e-d1ab-499a-8fb3-c29af95a853b /boot xfs defaults 0 0
/dev/mapper/klas-swap none swap defaults 0 0
[root@localhost ~]#
/etc/fstab (磁盘讲解)
作用: 开机自动挂载 笔试题
UUID=4c3bc84e-d1ab-499a-8fb3-c29af95a853b /boot xfs defaults 0 0
第一列: 设备的名称 可以是UUID 可以使用设备名称
第二列: 挂载点,设备的入口,类似通过/mnt进入cdrom
第三列: 文件系统类型
第四列: default 挂载参数,默认即可
第五列: 0 不自检 开机是否自检 1自检
第六列: 0 不备份 开机是否备份 1备
7、开机自动运行的服务
[root@localhost ~]#cat /etc/rc.local
#!/bin/bash
# THIS FILE IS ADDED FOR COMPATIBILITY PURPOSES
#
# It is highly advisable to create own systemd services or udev rules
# to run scripts during boot instead of using this file.
#
# In contrast to previous versions due to parallel execution during boot
# this script will NOT be run after all other services.
#
# Please note that you must run 'chmod +x /etc/rc.d/rc.local' to ensure
# that this script will be executed during boot.
touch /var/lock/subsys/local
[root@localhost ~]# 可以在这个文件中写入系统命令或者执行脚本的命令
/etc/rc.local #作用开机自动执行文件中的命令
第一步:只执行1次
执行命令:给文件增加可执行权限
[root@localhost ~]# chmod +x /etc/rc.local
第二步:往文件中写入命令
[root@localhost ~]# rm -rf * #(先清空家目录)
[root@localhost ~]# vim /etc/rc.local
mkdir -p /root/yunzhongzi{1..10}
esc :wq退出 reboot重启
root目录下会建立10个目录
--------------------这个别瞎用,当然了公司一般是不会让你用这个的
注意:删家
rm -rf ~
rm -rf /root/
会将root家目录删掉
rm -rf ~/*
rm -rf /root/*
会清空root目录下面的所有内容
--------------------
8、当前系统的运行级别文件
[root@localhost ~]#cat /etc/inittab
# inittab is no longer used.
#
# ADDING CONFIGURATION HERE WILL HAVE NO EFFECT ON YOUR SYSTEM.
#
# Ctrl-Alt-Delete is handled by /usr/lib/systemd/system/ctrl-alt-del.target
#
# systemd uses 'targets' instead of runlevels. By default, there are two main targets:
#
# multi-user.target: analogous to runlevel 3
# graphical.target: analogous to runlevel 5
#
# To view current default target, run:
# systemctl get-default
#
# To set a default target, run:
# systemctl set-default TARGET.target
[root@localhost ~]#
Linux系统的运行级别 runlever
0 #表示关机
1 #表示单用户
2 #表示多用户,但是不支持NFS
3 #表示完全多用户 默认所在的界面
4 #保留待开发
5 #表示图形界面
6 #表示重启
查看系统运行级别
[root@localhost ~]# runlevel
N 3
进入对应级别:
init 5 #自动重启进入到图形界面
init 0 #表示关机
init 6 #表示重启
9、开机自动显示里面的文字的文件
/etc/motd #作用 开机自动显示里面的文字 字符串
vim /etc/motd
[root@localhost ~]#cat /etc/motd
Authorized users only. All activities may be monitored and reported.
[root@localhost ~]#
自己的系统可以搞点花活,公司的系统就算了,显得不是很严肃
二、/proc下的配置文件
1、查看cpu的信息
[root@localhost ~]#cat /proc/cpuinfo
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 186
model name : 13th Gen Intel(R) Core(TM) i7-13620H
stepping : 2
microcode : 0xffffffff
cpu MHz : 2918.414
cache size : 24576 KB
physical id : 0
siblings : 2
core id : 0
cpu cores : 2
apicid : 0
initial apicid : 0
fpu : yes
fpu_exception : yes
cpuid level : 32
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ss ht syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon rep_good nopl xtopology tsc_reliable nonstop_tsc cpuid pni pclmulqdq ssse3 fma cx16 pcid sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c rdrand hypervisor lahf_lm abm 3dnowprefetch invpcid_single pti ssbd ibrs ibpb stibp fsgsbase tsc_adjust bmi1 avx2 smep bmi2 erms invpcid rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xgetbv1 xsaves arat umip gfni vaes vpclmulqdq rdpid movdiri movdir64b md_clear flush_l1d arch_capabilities
bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass l1tf mds swapgs
bogomips : 5836.82
clflush size : 64
cache_alignment : 64
address sizes : 45 bits physical, 48 bits virtual
power management:
processor : 1
vendor_id : GenuineIntel
cpu family : 6
model : 186
model name : 13th Gen Intel(R) Core(TM) i7-13620H
stepping : 2
microcode : 0xffffffff
cpu MHz : 2918.414
cache size : 24576 KB
physical id : 0
siblings : 2
core id : 1
cpu cores : 2
apicid : 1
initial apicid : 1
fpu : yes
fpu_exception : yes
cpuid level : 32
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ss ht syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon rep_good nopl xtopology tsc_reliable nonstop_tsc cpuid pni pclmulqdq ssse3 fma cx16 pcid sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c rdrand hypervisor lahf_lm abm 3dnowprefetch invpcid_single pti ssbd ibrs ibpb stibp fsgsbase tsc_adjust bmi1 avx2 smep bmi2 erms invpcid rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xgetbv1 xsaves arat umip gfni vaes vpclmulqdq rdpid movdiri movdir64b md_clear flush_l1d arch_capabilities
bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass l1tf mds swapgs
bogomips : 5836.82
clflush size : 64
cache_alignment : 64
address sizes : 45 bits physical, 48 bits virtual
power management:
processor : 2
vendor_id : GenuineIntel
cpu family : 6
model : 186
model name : 13th Gen Intel(R) Core(TM) i7-13620H
stepping : 2
microcode : 0xffffffff
cpu MHz : 2918.414
cache size : 24576 KB
physical id : 1
siblings : 2
core id : 0
cpu cores : 2
apicid : 2
initial apicid : 2
fpu : yes
fpu_exception : yes
cpuid level : 32
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ss ht syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon rep_good nopl xtopology tsc_reliable nonstop_tsc cpuid pni pclmulqdq ssse3 fma cx16 pcid sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c rdrand hypervisor lahf_lm abm 3dnowprefetch invpcid_single pti ssbd ibrs ibpb stibp fsgsbase tsc_adjust bmi1 avx2 smep bmi2 erms invpcid rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xgetbv1 xsaves arat umip gfni vaes vpclmulqdq rdpid movdiri movdir64b md_clear flush_l1d arch_capabilities
bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass l1tf mds swapgs
bogomips : 5836.82
clflush size : 64
cache_alignment : 64
address sizes : 45 bits physical, 48 bits virtual
power management:
processor : 3
vendor_id : GenuineIntel
cpu family : 6
model : 186
model name : 13th Gen Intel(R) Core(TM) i7-13620H
stepping : 2
microcode : 0xffffffff
cpu MHz : 2918.414
cache size : 24576 KB
physical id : 1
siblings : 2
core id : 1
cpu cores : 2
apicid : 3
initial apicid : 3
fpu : yes
fpu_exception : yes
cpuid level : 32
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 clflush mmx fxsr sse sse2 ss ht syscall nx pdpe1gb rdtscp lm constant_tsc arch_perfmon rep_good nopl xtopology tsc_reliable nonstop_tsc cpuid pni pclmulqdq ssse3 fma cx16 pcid sse4_1 sse4_2 x2apic movbe popcnt aes xsave avx f16c rdrand hypervisor lahf_lm abm 3dnowprefetch invpcid_single pti ssbd ibrs ibpb stibp fsgsbase tsc_adjust bmi1 avx2 smep bmi2 erms invpcid rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xgetbv1 xsaves arat umip gfni vaes vpclmulqdq rdpid movdiri movdir64b md_clear flush_l1d arch_capabilities
bugs : cpu_meltdown spectre_v1 spectre_v2 spec_store_bypass l1tf mds swapgs
bogomips : 5836.82
clflush size : 64
cache_alignment : 64
address sizes : 45 bits physical, 48 bits virtual
power management:
[root@localhost ~]#
lscpu #查看cpu的信息
[root@localhost ~]# lscpu
Architecture: x86_64
CPU op-mode(s): 32-bit, 64-bit
Byte Order: Little Endian
CPU(s): 1 #总核心的数量
On-line CPU(s) list: 0 #表示第一个核心 共1个核心
Thread(s) per core: 1
Core(s) per socket: 1
Socket(s): 1 #cpu的个数
2、查看内存的信息
[root@localhost ~]#cat /proc/meminfo
MemTotal: 2003648 kB
MemFree: 1344132 kB
MemAvailable: 1516508 kB
Buffers: 2708 kB
Cached: 374736 kB
SwapCached: 0 kB
Active: 211556 kB
Inactive: 241228 kB
Active(anon): 124116 kB
Inactive(anon): 47996 kB
Active(file): 87440 kB
Inactive(file): 193232 kB
Unevictable: 0 kB
Mlocked: 0 kB
SwapTotal: 2097148 kB
SwapFree: 2097148 kB
Dirty: 56 kB
Writeback: 0 kB
AnonPages: 73400 kB
Mapped: 103992 kB
Shmem: 96772 kB
KReclaimable: 46444 kB
Slab: 85368 kB
SReclaimable: 46444 kB
SUnreclaim: 38924 kB
KernelStack: 5360 kB
PageTables: 3336 kB
NFS_Unstable: 0 kB
Bounce: 0 kB
WritebackTmp: 0 kB
CommitLimit: 3098972 kB
Committed_AS: 461544 kB
VmallocTotal: 34359738367 kB
VmallocUsed: 0 kB
VmallocChunk: 0 kB
Percpu: 80896 kB
HardwareCorrupted: 0 kB
AnonHugePages: 4096 kB
ShmemHugePages: 0 kB
ShmemPmdMapped: 0 kB
HugePages_Total: 0
HugePages_Free: 0
HugePages_Rsvd: 0
HugePages_Surp: 0
Hugepagesize: 2048 kB
Hugetlb: 0 kB
DirectMap4k: 132992 kB
DirectMap2M: 1964032 kB
DirectMap1G: 0 kB
[root@localhost ~]#
free #查看内存的信息
[root@localhost ~]# free -h
总大小 使用 空闲 共享内存 缓存 缓冲 可用
total used free shared buff/cache available
Mem: 1.9G 203M 1.6G 9.5M 104M 1.6G
Swap: 2.0G 0B 2.0G
3、查看负载的信息
[root@localhost ~]#cat /proc/loadavg
1.90 1.68 1.58 6/216 3744616
uptime #查看系统负载
[root@localhost ~]# uptime
16:25:09 up 13 min, 2 users, load average: 0.08, 0.08, 0.07
当前时间 运行时常 2个登录使用 平均负载 1分钟 5分钟 15分钟
系统负载:
系统负载是衡量操作系统繁忙程度
如果负载和cpu核心数量的数字相同说明系统繁忙
例如 :cpu是2核,则负载不能超过2,接近于2,说明系统繁忙
w #查看系统负载和用户登录信息
[root@localhost ~]# w
16:29:52 up 17 min, 2 users, load average: 0.07, 0.05, 0.05
登录用户 终端 哪个IP连接的 登陆时间 当前执行的命令
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
root pts/0 10.0.0.1 16:05 24:16 0.02s 0.02s -bash
root pts/1 10.0.0.1 16:16 0.00s 0.06s 0.03s w
4、查看挂载的信息
[root@localhost ~]#cat /proc/mounts
sysfs /sys sysfs rw,nosuid,nodev,noexec,relatime 0 0
proc /proc proc rw,nosuid,nodev,noexec,relatime 0 0
devtmpfs /dev devtmpfs rw,nosuid,size=985640k,nr_inodes=246410,mode=755 0 0
securityfs /sys/kernel/security securityfs rw,nosuid,nodev,noexec,relatime 0 0
tmpfs /dev/shm tmpfs rw,nosuid,nodev 0 0
devpts /dev/pts devpts rw,nosuid,noexec,relatime,gid=5,mode=620,ptmxmode=000 0 0
tmpfs /run tmpfs rw,nosuid,nodev,mode=755 0 0
tmpfs /sys/fs/cgroup tmpfs ro,nosuid,nodev,noexec,mode=755 0 0
cgroup /sys/fs/cgroup/systemd cgroup rw,nosuid,nodev,noexec,relatime,xattr,release_agent=/usr/lib/systemd/systemd-cgroups-agent,name=systemd 0 0
pstore /sys/fs/pstore pstore rw,nosuid,nodev,noexec,relatime 0 0
bpf /sys/fs/bpf bpf rw,nosuid,nodev,noexec,relatime,mode=700 0 0
cgroup /sys/fs/cgroup/cpu,cpuacct cgroup rw,nosuid,nodev,noexec,relatime,cpu,cpuacct 0 0
cgroup /sys/fs/cgroup/memory cgroup rw,nosuid,nodev,noexec,relatime,memory 0 0
cgroup /sys/fs/cgroup/pids cgroup rw,nosuid,nodev,noexec,relatime,pids 0 0
cgroup /sys/fs/cgroup/hugetlb cgroup rw,nosuid,nodev,noexec,relatime,hugetlb 0 0
cgroup /sys/fs/cgroup/net_cls,net_prio cgroup rw,nosuid,nodev,noexec,relatime,net_cls,net_prio 0 0
cgroup /sys/fs/cgroup/perf_event cgroup rw,nosuid,nodev,noexec,relatime,perf_event 0 0
cgroup /sys/fs/cgroup/rdma cgroup rw,nosuid,nodev,noexec,relatime,rdma 0 0
cgroup /sys/fs/cgroup/devices cgroup rw,nosuid,nodev,noexec,relatime,devices 0 0
cgroup /sys/fs/cgroup/blkio cgroup rw,nosuid,nodev,noexec,relatime,blkio 0 0
cgroup /sys/fs/cgroup/cpuset cgroup rw,nosuid,nodev,noexec,relatime,cpuset 0 0
cgroup /sys/fs/cgroup/freezer cgroup rw,nosuid,nodev,noexec,relatime,freezer 0 0
configfs /sys/kernel/config configfs rw,nosuid,nodev,noexec,relatime 0 0
/dev/mapper/klas-root / xfs rw,relatime,attr2,inode64,noquota 0 0
systemd-1 /proc/sys/fs/binfmt_misc autofs rw,relatime,fd=30,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=21578 0 0
mqueue /dev/mqueue mqueue rw,nosuid,nodev,noexec,relatime 0 0
hugetlbfs /dev/hugepages hugetlbfs rw,relatime,pagesize=2M 0 0
debugfs /sys/kernel/debug debugfs rw,nosuid,nodev,noexec,relatime 0 0
tmpfs /tmp tmpfs rw,nosuid,nodev 0 0
/dev/sda1 /boot xfs rw,relatime,attr2,inode64,noquota 0 0
sunrpc /var/lib/nfs/rpc_pipefs rpc_pipefs rw,relatime 0 0
tmpfs /run/user/0 tmpfs rw,nosuid,nodev,relatime,size=200364k,mode=700 0 0
df #查看磁盘信息
[root@localhost ~]# df -h
硬件名称 大小 使用 可用 使用百分比 挂载点
Filesystem Size Used Avail Use% Mounted on
devtmpfs 980M 0 980M 0% /dev
tmpfs 991M 0 991M 0% /dev/shm
tmpfs 991M 9.6M 981M 1% /run
tmpfs 991M 0 991M 0% /sys/fs/cgroup
/dev/sda3 18G 2.0G 16G 11% /
/dev/sda1 197M 110M 88M 56% /boot
tmpfs 199M 0 199M 0% /run/user/0
三、/var目录下的重要文件
1、系统日志文件
[root@localhost ~]#tail /var/log/messages
Nov 20 17:42:23 localhost sshd[1752]: mm_audit_run_command entering command export LANG="en_US";export LANGUAGE="en_US";export LC_ALL="en_US";free;echo finalshell_separator;uptime;echo finalshell_separator;cat /proc/net/dev;echo finalshell_separator;df;echo finalshell_separator;sleep 1;free;echo finalshell_separator;uptime;echo finalshell_separator;cat /proc/net/dev;echo finalshell_separator;df;echo finalshell_separator;
Nov 20 17:42:24 localhost sshd[10499]: Starting session: command for root from 10.0.0.1 port 57532 id 8
Nov 20 17:42:24 localhost sshd[10499]: mm_audit_run_command entering command ls --color=never -l /proc/*/exe
Nov 20 17:42:24 localhost sshd[10499]: Starting session: command for root from 10.0.0.1 port 57532 id 6
Nov 20 17:42:24 localhost sshd[10499]: mm_audit_run_command entering command ps -HewO lstart ex |grep -E "3804096|3804137|3804144|3804159|COMMAND"
Nov 20 17:42:24 localhost sshd[10499]: Close session: user root from 10.0.0.1 port 57532 id 8
Nov 20 17:42:24 localhost sshd[10499]: Close session: user root from 10.0.0.1 port 57532 id 6
Nov 20 17:42:24 localhost sshd[10499]: Starting session: command for root from 10.0.0.1 port 57532 id 6
Nov 20 17:42:24 localhost sshd[10499]: mm_audit_run_command entering command ps -HewO lstart ex
Nov 20 17:42:24 localhost sshd[10499]: Close session: user root from 10.0.0.1 port 57532 id 6
2、系统登录和退出日志
[root@localhost ~]#tail /var/log/secure
Nov 20 09:16:25 localhost polkitd[772]: Loading rules from directory /etc/polkit-1/rules.d
Nov 20 09:16:25 localhost polkitd[772]: Loading rules from directory /usr/share/polkit-1/rules.d
Nov 20 09:16:25 localhost polkitd[772]: Finished loading, compiling and executing 5 rules
Nov 20 09:16:25 localhost polkitd[772]: Acquired the name org.freedesktop.PolicyKit1 on the system bus
Nov 20 09:16:35 localhost systemd[1153]: pam_unix(systemd-user:session): session opened for user root(uid=0) by (uid=0)
Nov 20 09:16:35 localhost login[937]: pam_unix(login:session): session opened for user root(uid=0) by LOGIN(uid=0)
Nov 20 09:16:36 localhost login[937]: ROOT LOGIN ON tty1
Nov 20 09:16:58 localhost sshd[1218]: pam_unix(sshd:session): session opened for user root(uid=0) by (uid=0)
Nov 20 10:59:15 localhost sshd[1742]: pam_unix(sshd:session): session opened for user root(uid=0) by (uid=0)
Nov 20 11:01:07 localhost sshd[10402]: pam_unix(sshd:session): session opened for user root(uid=0) by (uid=0)
[root@localhost ~]#
如果secure日志出现大量Failed说明有人暴力破解服务器密码
最新的日志在最下面
3、服务日志
服务日志是自定义的,根据服务需求定义到指定的文件
默认的服务:Nginx服务 自身日志
/var/log/nginx/nginx.log
有些服务会默认将部分日志输出到message系统日志中
上边用到了tail这个命令的作用是什么呢?下篇文章分解
想成为大佬,就要从小白开始,从0开始,一点一点的积累,慢慢成长,终有一日可以成为令别人仰望的大佬!!