| Time | User | IP / Host | Terminal | Status |
|---|---|---|---|---|
| 2026-10-11 19:22:17 | root | 198.51.100.27 |
— | Not blocked |
| 2026-10-11 11:44:59 | root | 198.51.100.33 |
— | Not blocked |
| 2026-10-11 16:54:49 | root | 198.51.100.19 |
— | Not blocked |
| 2026-10-11 14:29:59 | root | 198.51.100.17 |
— | Not blocked |
| 2026-10-11 15:08:01 | root | 198.51.100.34 |
— | Not blocked |
| 2026-10-11 09:26:57 | root | 198.51.100.17 |
— | Not blocked |
| 2026-10-10 12:41:41 | root | 198.51.100.29 |
— | Not blocked |
| 2026-10-11 01:07:01 | root | 198.51.100.23 |
— | Not blocked |
| Time | User | Command | Result |
|---|---|---|---|
| 2026-10-11 19:22:17 | admin | /usr/bin/systemctl status fail2ban |
OK |
| 2026-10-11 19:06:29 | admin | /usr/bin/apt update |
OK |
| 2026-10-11 18:50:41 | admin | /usr/sbin/ufw status |
OK |
| 2026-10-11 18:32:08 | admin | /usr/bin/tail -f /var/log/auth.log |
OK |
| 2026-10-11 17:47:13 | admin | /usr/bin/docker ps |
OK |
| 2026-10-11 15:18:12 | admin | /usr/sbin/fail2ban-client status |
OK |
| 2026-10-11 17:44:41 | admin | /usr/bin/systemctl restart nginx |
OK |
| 2026-10-11 14:27:35 | admin | /usr/bin/journalctl -u sshd |
OK |
| 2026-10-11 16:24:01 | admin | /usr/sbin/aa-status |
OK |
| 2026-10-11 13:07:53 | admin | /usr/bin/crontab -l |
OK |
| 2026-10-11 17:34:17 | admin | /usr/sbin/lynis audit system |
OK |
| 2026-10-11 12:16:57 | admin | /usr/bin/cscli decisions list |
OK |
| 2026-10-11 14:07:17 | admin | /usr/bin/systemctl status fail2ban |
OK |
| 2026-10-11 11:42:18 | admin | /usr/bin/apt update |
OK |
| 2026-10-11 09:09:19 | admin | /usr/sbin/ufw status |
OK |
| 2026-10-11 10:23:47 | admin | /usr/bin/tail -f /var/log/auth.log |
OK |
| 2026-10-11 15:45:29 | admin | /usr/bin/docker ps |
OK |
| 2026-10-11 15:24:51 | admin | /usr/sbin/fail2ban-client status |
OK |
| 2026-10-11 10:21:23 | admin | /usr/bin/systemctl restart nginx |
OK |
| 2026-10-11 09:45:38 | admin | /usr/bin/journalctl -u sshd |
OK |
| 2026-10-11 05:33:57 | admin | /usr/sbin/aa-status |
OK |
| 2026-10-11 08:37:56 | admin | /usr/bin/crontab -l |
OK |
| 2026-10-11 06:51:43 | admin | /usr/sbin/lynis audit system |
OK |
| 2026-10-11 04:00:45 | admin | /usr/bin/cscli decisions list |
OK |
| 2026-10-11 10:28:17 | admin | /usr/bin/systemctl status fail2ban |
OK |
| 2026-10-11 14:14:47 | admin | /usr/bin/apt update |
OK |
| 2026-10-11 00:59:01 | admin | /usr/sbin/ufw status |
OK |
| 2026-10-11 01:28:08 | admin | /usr/bin/tail -f /var/log/auth.log |
OK |
| 2026-10-11 11:21:37 | admin | /usr/bin/docker ps |
OK |
| 2026-10-11 01:45:14 | admin | /usr/sbin/fail2ban-client status |
OK |
| 2026-10-11 11:30:17 | admin | /usr/bin/systemctl restart nginx |
OK |
| 2026-10-11 12:35:09 | admin | /usr/bin/journalctl -u sshd |
OK |
| 2026-10-11 05:32:57 | admin | /usr/sbin/aa-status |
OK |
| 2026-10-11 06:18:32 | admin | /usr/bin/crontab -l |
OK |
| 2026-10-11 05:19:39 | admin | /usr/sbin/lynis audit system |
OK |
| Time | Type | User | IP / Host | Result | Status |
|---|---|---|---|---|---|
| 2026-10-11 19:22:17 | USER_LOGIN | admin | 203.0.113.20 |
OK | Not blocked |
| 2026-10-11 13:03:46 | USER_LOGIN | admin | 203.0.113.20 |
OK | Not blocked |
| 2026-10-11 07:24:53 | USER_LOGIN | admin | 203.0.113.20 |
OK | Not blocked |
| 2026-10-11 07:15:50 | USER_LOGIN | admin | 203.0.113.20 |
OK | Not blocked |
| 2026-10-10 21:46:01 | USER_LOGIN | admin | 203.0.113.20 |
OK | Not blocked |
The Linux audit daemon records exactly what you ask it to and nothing more, which makes it the most precise tool on the server and the least pleasant to query. ausearch and aureport work, but they assume you already know what you are looking for and remember the flag that finds it.
This page shows the audit rules currently loaded, the paths and syscalls being watched, and the most recent events with their type, the process responsible and the outcome. Being able to see the loaded rules matters as much as seeing the events: an empty rule set is the most common reason auditd appears to be running but recording nothing of value.
A reasonable starting set watches /etc/passwd and /etc/shadow for changes, /etc/ssh/sshd_config for edits, and execution of privilege escalation binaries. Those four cover the traces most intrusions leave behind, without burying the log in noise from ordinary work.