Exercise

Finding Recently Modified Logs Exercise

Task

Record which files under /var/log change while you are away from the console. Schedule the search to run once, two minutes from now, and save what it finds.

Host
servera
Search
/var/log, modified in the last two minutes
Output file
/tmp/log_audit
  1. Install at and start atd

    The at package is not part of a minimal RHEL installation, so install it first.

    sudo dnf install -y at

    Installing the package enables atd at boot, but does not start it now. Start it yourself and confirm the change.

    systemctl is-active atd
    sudo systemctl start atd
    systemctl is-active atd
  2. Build the search

    Write a line into the system log first, so the search has something recent to find.

    logger "IT-230 log audit"

    Now search /var/log for files modified in the last two minutes.

    find /var/log -mmin -2

    Send standard error to /dev/null so only the matches remain.

    find /var/log -mmin -2 2>/dev/null
  3. Schedule it two minutes from now

    A deferred job has no terminal to print to, so send the results to a file. Confirm that file does not exist yet, so its appearance later proves the job ran.

    ls /tmp/log_audit

    Pipe the command into at, which reads what to run from standard input.

    echo "find /var/log -mmin -2 > /tmp/log_audit 2>/dev/null" | at now +2min

    at replies with the job number and the time the job will run. Note the number down; the next step needs it.

  4. Inspect the pending job

    List the jobs you have waiting.

    atq

    Each line gives the job number, when it runs, the queue it sits on, and the user it runs as. Read the job back to see exactly what atd will run.

    at -c 1
  5. Confirm the job ran

    Wait until the scheduled time has passed. Then read the cron log, where atd records the job starting.

    sudo less /var/log/cron

    Press G to jump to the end of the file and q to quit. Look for a line naming your job number and user:

    atd[11251]: Starting job 1 (a0000101c6de61) for user 'student' (1000)

    Then check what the job actually wrote.

    ls -l /tmp/log_audit
    cat /tmp/log_audit
  6. Clean up

    The queue should be empty now that the job has run: a job leaves the queue whether it succeeded or failed. Remove the file the job wrote.

    atq
    rm /tmp/log_audit