{"id":687,"date":"2010-03-05T21:03:07","date_gmt":"2010-03-05T19:03:07","guid":{"rendered":"http:\/\/avz.org.ua\/wp\/?p=687"},"modified":"2012-02-15T12:06:03","modified_gmt":"2012-02-15T10:06:03","slug":"samba-detailed-logging","status":"publish","type":"post","link":"https:\/\/avz.org.ua\/wp\/2010\/03\/05\/samba-detailed-logging\/","title":{"rendered":"\u0414\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0435 \u043b\u043e\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 Samba"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/avz.org.ua\/wp\/wp-content\/uploads\/2010\/03\/magnifying-glass-200x150.jpg\" alt=\"\" title=\"magnifying-glass\" width=\"200\" height=\"150\" class=\"pic\" \/>\u0418\u043d\u043e\u0433\u0434\u0430 \u043d\u0443 \u043e\u0447\u0435\u043d\u044c \u043d\u0443\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u043a\u0442\u043e \u0436\u0435 \u0441\u043e\u0437\u0434\u0430\u043b \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u043b \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0441 \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430. \u0421\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0439 \u043b\u043e\u0433-\u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 Samba \u043f\u0438\u0448\u0435\u0442 \u043f\u0440\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 \u043f\u043e-\u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, \u043d\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u044d\u0442\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c, \u0442\u0430\u043a \u043a\u0430\u043a \u0432 \u043d\u0435\u0433\u043e \u043f\u0438\u0448\u0443\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u043e\u0431\u044b\u0442\u0438\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043e\u0442 \u043e\u0431\u0449\u0438\u0445 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432. \u041f\u0440\u0438\u043c\u0435\u0440 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0433\u043e \u043b\u043e\u0433-\u0444\u0430\u0439\u043b\u0430:<br \/>\n<\/p>\n<div class=\"code\">\n[2010\/03\/05 20:45:00, 1] smbd\/service.c:make_connection_snum(1042)<br \/>\n  host44 (10.44.44.44) connect to service PUB initially as user vasya (uid=503, gid=501) (pid 2707)<br \/>\n[2010\/03\/05 20:47:34, 1] smbd\/service.c:close_cnum(1239)<br \/>\n  host44 (10.44.44.44) closed connection to service PUB\n<\/div>\n<p>\u0427\u0442\u043e\u0431\u044b \u043b\u043e\u0433-\u0444\u0430\u0439\u043b \u0431\u044b\u043b \u0431\u043e\u043b\u0435\u0435 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u044b\u043c, \u0432 <strong>smb.conf<\/strong> \u043d\u0443\u0436\u043d\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0442\u0440\u043e\u043a\u0438:<\/p>\n<pre lang=\"text\" class=\"1\">\r\nlog level = 0 vfs:2\r\nmax log size = 0\r\nsyslog = 0\r\n\r\n[PUBLIC]\r\n  comment = writeable folder\r\n  path = \/var\/spool\/samba\/public\r\n  valid users = @admins\r\n  public = yes\r\n  writable = yes\r\n  printable = no\r\n  vfs objects = full_audit\r\n  full_audit:prefix = %u|%I\r\n  full_audit:failure = none\r\n  full_audit:success = mkdir rmdir open read pread write pwrite sendfile rename unlink lock\r\n  full_audit:facility = local5\r\n  full_audit:priority = debug\r\n<\/pre>\n<p>\u0412 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u0445 \u0448\u0430\u0440\u044b \u0432\u0441\u0435, \u0447\u0442\u043e \u043a\u0430\u0441\u0430\u0435\u0442\u0441\u044f \u043b\u043e\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f, \u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u0435\u043d\u043e \u0432 \u0441\u0442\u0440\u043e\u043a\u0430\u0445 12-17. \u0412 13-\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0435 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043f\u0440\u0435\u0444\u0438\u043a\u0441 (\u043b\u043e\u0433\u0438\u043d \u0438 IP-\u0430\u0434\u0440\u0435\u0441 \u043a\u043b\u0438\u0435\u043d\u0442\u0430). \u0412 15-\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0435 \u043f\u0435\u0440\u0435\u0447\u0438\u0441\u043b\u044f\u0435\u043c \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0434\u043e\u043b\u0436\u043d\u044b \u043f\u043e\u0434\u0432\u0435\u0440\u0433\u0430\u0442\u044c\u0441\u044f \u0430\u0443\u0434\u0438\u0442\u0443 (\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u0443\u0434\u0443\u0442 \u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u043b\u043e\u0433-\u0444\u0430\u0439\u043b). \u0412 16-\u043e\u0439 \u0438 17-\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0430\u0445 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u043c \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b \u0434\u043b\u044f syslog. \u0417\u0430\u0442\u0435\u043c \u0432 <strong>\/etc\/syslog.conf<\/strong> \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u0441\u0442\u0440\u043e\u043a\u0443<\/p>\n<pre lang=\"text\">\r\nlocal5.debug  -\/var\/log\/samba\/audit.log\r\n<\/pre>\n<p>\u0438 \u043f\u043e\u0441\u044b\u043b\u0430\u0435\u043c syslog-\u0443 \u0441\u0438\u0433\u043d\u0430\u043b HUP \u0447\u0442\u043e\u0431\u044b \u0442\u043e\u0442 \u043f\u0435\u0440\u0435\u0447\u0438\u0442\u0430\u043b \u0441\u0432\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433. \u0417\u043d\u0430\u043a \u043c\u0438\u043d\u0443\u0441\u0430 \u043f\u0435\u0440\u0435\u0434 \u0438\u043c\u0435\u043d\u0435\u043c \u0444\u0430\u0439\u043b\u0430 \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442, \u0447\u0442\u043e \u043f\u043e\u0441\u043b\u0435 \u043a\u0430\u0436\u0434\u043e\u0439 \u0437\u0430\u043f\u0438\u0441\u0438 \u0432 \u0444\u0430\u0439\u043b \u043d\u0435 \u0431\u0443\u0434\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0442\u044c\u0441\u044f \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u044f sync, \u0430 \u0434\u0430\u043d\u043d\u044b\u0435 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0431\u0443\u0434\u0443\u0442 \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 \u043e\u043f\u0435\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432 \u0434\u0438\u0441\u043a\u043e\u0432\u043e\u043c \u0431\u0443\u0444\u0435\u0440\u0435. \u041f\u0440\u0438 \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0438\u043d\u0442\u0435\u043d\u0441\u0438\u0432\u043d\u043e\u0441\u0442\u0438 \u043f\u043e\u0442\u043e\u043a\u0430 \u0437\u0430\u043f\u0438\u0441\u0435\u0439 \u044d\u0442\u043e \u0443\u043c\u0435\u043d\u044c\u0448\u0430\u0435\u0442 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u043d\u0430 \u0434\u0438\u0441\u043a\u043e\u0432\u0443\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u0443.<\/p>\n<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0432 \u0444\u0430\u0439\u043b\u0435 \/var\/log\/samba\/audit.log \u043f\u043e\u044f\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u0442\u0430\u043a\u0438\u0435 \u0437\u0430\u043f\u0438\u0441\u0438:<\/p>\n<div class=\"code\">\nMar 5 21:04:01 serv smbd_audit: vasya|10.44.44.44|pwrite|ok|dir1\/somefile.exe<br \/>\nMar 5 21:04:01 serv smbd_audit: ann|10.44.44.92|open|ok|r|dir2\/database.txt<br \/>\nMar 5 21:04:01 serv smbd_audit: editor|10.44.44.34|pread|ok|dir1\/somefile.exe\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u0418\u043d\u043e\u0433\u0434\u0430 \u043d\u0443 \u043e\u0447\u0435\u043d\u044c \u043d\u0443\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u043a\u0442\u043e \u0436\u0435 \u0441\u043e\u0437\u0434\u0430\u043b \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u043b \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0441 \u0444\u0430\u0439\u043b\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430. \u0421\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0439 \u043b\u043e\u0433-\u0444\u0430\u0439\u043b, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 Samba \u043f\u0438\u0448\u0435\u0442 \u043f\u0440\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 \u043f\u043e-\u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e, \u043d\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u044d\u0442\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c, \u0442\u0430\u043a \u043a\u0430\u043a \u0432 \u043d\u0435\u0433\u043e \u043f\u0438\u0448\u0443\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u043e\u0431\u044b\u0442\u0438\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043e\u0442 \u043e\u0431\u0449\u0438\u0445 \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432. \u041f\u0440\u0438\u043c\u0435\u0440 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e\u0433\u043e \u043b\u043e\u0433-\u0444\u0430\u0439\u043b\u0430: [2010\/03\/05 20:45:00, 1] smbd\/service.c:make_connection_snum(1042) host44 (10.44.44.44) connect to service PUB initially as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,21],"tags":[46],"class_list":["post-687","post","type-post","status-publish","format-standard","hentry","category-nix","category-tips-and-tricks","tag-samba"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/posts\/687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/comments?post=687"}],"version-history":[{"count":0,"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/posts\/687\/revisions"}],"wp:attachment":[{"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/media?parent=687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/categories?post=687"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avz.org.ua\/wp\/wp-json\/wp\/v2\/tags?post=687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}