Cyked
March 20th, 2009, 05:15 PM
Yesterday my auth.log had a bunch of entries going back to the 15th. Today when I looked at it I only have the lines from just having ssh'd in. Why would it purge like that, something I need to check?
I'm seeing these every 17 and 39 of the hour.
Mar 20 08:17:02 tux CRON[29338]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 20 08:17:02 tux CRON[29338]: pam_unix(cron:session): session closed for user root
Mar 20 08:39:01 tux CRON[29719]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 20 08:39:01 tux CRON[29719]: pam_unix(cron:session): session closed for user root
I'm seeing these every 17 and 39 of the hour.
Mar 20 08:17:02 tux CRON[29338]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 20 08:17:02 tux CRON[29338]: pam_unix(cron:session): session closed for user root
Mar 20 08:39:01 tux CRON[29719]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 20 08:39:01 tux CRON[29719]: pam_unix(cron:session): session closed for user root