Auditd

auditd — system audit
Cache: 19:22:17 Refresh
Detected 8 login attempts from external IPs
Logins today: 5  |  Sudo: 35  |  Blocked: / 8  |  User: admin
Logins today
5
External login attempts
8
Sudo today
35
Log
13
External login attempts (8)
TimeUserIP / HostTerminalStatus
2026-10-11 19:22:17 root 198.51.100.27 — Not blocked
2026-10-11 11:44:59 root 198.51.100.33 — Not blocked
2026-10-11 16:54:49 root 198.51.100.19 — Not blocked
2026-10-11 14:29:59 root 198.51.100.17 — Not blocked
2026-10-11 15:08:01 root 198.51.100.34 — Not blocked
2026-10-11 09:26:57 root 198.51.100.17 — Not blocked
2026-10-10 12:41:41 root 198.51.100.29 — Not blocked
2026-10-11 01:07:01 root 198.51.100.23 — Not blocked
Sudo commands today 35 significant / 35 total
TimeUserCommandResult
2026-10-11 19:22:17 admin /usr/bin/systemctl status fail2ban OK
2026-10-11 19:06:29 admin /usr/bin/apt update OK
2026-10-11 18:50:41 admin /usr/sbin/ufw status OK
2026-10-11 18:32:08 admin /usr/bin/tail -f /var/log/auth.log OK
2026-10-11 17:47:13 admin /usr/bin/docker ps OK
2026-10-11 15:18:12 admin /usr/sbin/fail2ban-client status OK
2026-10-11 17:44:41 admin /usr/bin/systemctl restart nginx OK
2026-10-11 14:27:35 admin /usr/bin/journalctl -u sshd OK
2026-10-11 16:24:01 admin /usr/sbin/aa-status OK
2026-10-11 13:07:53 admin /usr/bin/crontab -l OK
2026-10-11 17:34:17 admin /usr/sbin/lynis audit system OK
2026-10-11 12:16:57 admin /usr/bin/cscli decisions list OK
2026-10-11 14:07:17 admin /usr/bin/systemctl status fail2ban OK
2026-10-11 11:42:18 admin /usr/bin/apt update OK
2026-10-11 09:09:19 admin /usr/sbin/ufw status OK
2026-10-11 10:23:47 admin /usr/bin/tail -f /var/log/auth.log OK
2026-10-11 15:45:29 admin /usr/bin/docker ps OK
2026-10-11 15:24:51 admin /usr/sbin/fail2ban-client status OK
2026-10-11 10:21:23 admin /usr/bin/systemctl restart nginx OK
2026-10-11 09:45:38 admin /usr/bin/journalctl -u sshd OK
2026-10-11 05:33:57 admin /usr/sbin/aa-status OK
2026-10-11 08:37:56 admin /usr/bin/crontab -l OK
2026-10-11 06:51:43 admin /usr/sbin/lynis audit system OK
2026-10-11 04:00:45 admin /usr/bin/cscli decisions list OK
2026-10-11 10:28:17 admin /usr/bin/systemctl status fail2ban OK
2026-10-11 14:14:47 admin /usr/bin/apt update OK
2026-10-11 00:59:01 admin /usr/sbin/ufw status OK
2026-10-11 01:28:08 admin /usr/bin/tail -f /var/log/auth.log OK
2026-10-11 11:21:37 admin /usr/bin/docker ps OK
2026-10-11 01:45:14 admin /usr/sbin/fail2ban-client status OK
2026-10-11 11:30:17 admin /usr/bin/systemctl restart nginx OK
2026-10-11 12:35:09 admin /usr/bin/journalctl -u sshd OK
2026-10-11 05:32:57 admin /usr/sbin/aa-status OK
2026-10-11 06:18:32 admin /usr/bin/crontab -l OK
2026-10-11 05:19:39 admin /usr/sbin/lynis audit system OK
Logins / logouts today (5)
TimeTypeUserIP / HostResultStatus
2026-10-11 19:22:17 USER_LOGIN admin 203.0.113.20 OK Not blocked
2026-10-11 13:03:46 USER_LOGIN admin 203.0.113.20 OK Not blocked
2026-10-11 07:24:53 USER_LOGIN admin 203.0.113.20 OK Not blocked
2026-10-11 07:15:50 USER_LOGIN admin 203.0.113.20 OK Not blocked
2026-10-10 21:46:01 USER_LOGIN admin 203.0.113.20 OK Not blocked
/var/log/audit/audit.log

An auditd web UI for logs ausearch makes hard work

The Linux audit daemon records exactly what you ask it to and nothing more, which makes it the most precise tool on the server and the least pleasant to query. ausearch and aureport work, but they assume you already know what you are looking for and remember the flag that finds it.

This page shows the audit rules currently loaded, the paths and syscalls being watched, and the most recent events with their type, the process responsible and the outcome. Being able to see the loaded rules matters as much as seeing the events: an empty rule set is the most common reason auditd appears to be running but recording nothing of value.

A reasonable starting set watches /etc/passwd and /etc/shadow for changes, /etc/ssh/sshd_config for edits, and execution of privilege escalation binaries. Those four cover the traces most intrusions leave behind, without burying the log in noise from ordinary work.