Exercise
Finding Recently Modified Logs Exercise
Task
Record which files under /var/log change
while you are away from the console. Schedule the search
to run once, two minutes from now, and save what it
finds.
- Host
servera- Search
-
/var/log, modified in the last two minutes - Output file
/tmp/log_audit
-
Install
atand startatdThe
atpackage is not part of a minimal RHEL installation, so install it first.sudo dnf install -y atInstalling the package enables
atdat boot, but does not start it now. Start it yourself and confirm the change.systemctl is-active atd sudo systemctl start atd systemctl is-active atd -
Build the search
Write a line into the system log first, so the search has something recent to find.
logger "IT-230 log audit"Now search
/var/logfor files modified in the last two minutes.find /var/log -mmin -2Send standard error to
/dev/nullso only the matches remain.find /var/log -mmin -2 2>/dev/null -
Schedule it two minutes from now
A deferred job has no terminal to print to, so send the results to a file. Confirm that file does not exist yet, so its appearance later proves the job ran.
ls /tmp/log_auditPipe the command into
at, which reads what to run from standard input.echo "find /var/log -mmin -2 > /tmp/log_audit 2>/dev/null" | at now +2minatreplies with the job number and the time the job will run. Note the number down; the next step needs it. -
Inspect the pending job
List the jobs you have waiting.
atqEach line gives the job number, when it runs, the queue it sits on, and the user it runs as. Read the job back to see exactly what
atdwill run.at -c 1 -
Confirm the job ran
Wait until the scheduled time has passed. Then read the cron log, where
atdrecords the job starting.sudo less /var/log/cronPress G to jump to the end of the file and q to quit. Look for a line naming your job number and user:
atd[11251]: Starting job 1 (a0000101c6de61) for user 'student' (1000)Then check what the job actually wrote.
ls -l /tmp/log_audit cat /tmp/log_audit -
Clean up
The queue should be empty now that the job has run: a job leaves the queue whether it succeeded or failed. Remove the file the job wrote.
atq rm /tmp/log_audit