{"id":51,"date":"2019-11-25T10:24:11","date_gmt":"2019-11-25T10:24:11","guid":{"rendered":"http:\/\/www.betterit360.com\/?p=51"},"modified":"2019-11-25T10:24:11","modified_gmt":"2019-11-25T10:24:11","slug":"linux-history%e6%93%8d%e4%bd%9c%e6%97%a5%e5%bf%97%e9%85%8d%e7%bd%ae","status":"publish","type":"post","link":"http:\/\/www.betterit360.com\/?p=51","title":{"rendered":"Linux History\u64cd\u4f5c\u65e5\u5fd7\u914d\u7f6e"},"content":{"rendered":"\n<p>History\u8bb0\u5f55\u4e86\u7528\u6237\u64cd\u4f5c\u547d\u4ee4\uff0c\u4f46\u6ca1\u6709\u8bb0\u5f55\u6765\u6e90ip\u5730\u5740\u3001\u64cd\u4f5c\u7528\u6237\u3001\u64cd\u4f5c\u65f6\u95f4\u7b49\uff0c\u4e14\u7528\u6237\u53ef\u4ee5\u6e05\u7a7aHistory\u8bb0\u5f55\uff0c\u4e00\u65e6\u670d\u52a1\u5668\u51fa\u73b0\u95ee\u9898\uff0c\u5f88\u96be\u8c03\u67e5\u53d6\u8bc1\u548c\u5ba1\u8ba1\u7528\u6237\u64cd\u4f5c\u3002<\/p>\n\n\n\n<p>\u5728\u6ca1\u6709\u5821\u5792\u673a\u7684\u60c5\u51b5\u4e0b\uff0c\u53ef\u4ee5\u901a\u8fc7logger\u5c06History\u4e2d\u7684\u64cd\u4f5c\u547d\u4ee4\u8bb0\u5f55\u5230\u7cfb\u7edf\u65e5\u5fd7\u4e2d\u3002\u6b64\u65b9\u6cd5\u5b9e\u65f6\u8bb0\u5f55\u7528\u6237\u64cd\u4f5c\uff0c\u4e14\u8bb0\u5f55\u6765\u6e90ip\u5730\u5740\u3001\u64cd\u4f5c\u7528\u6237\u3001\u64cd\u4f5c\u65f6\u95f4\u3001\u64cd\u4f5c\u547d\u4ee4\u7b49\u3002<\/p>\n\n\n\n<p><strong>HISTORY\u65e5\u5fd7\u914d\u7f6e\u6b65\u9aa4\uff1a<\/strong><\/p>\n\n\n\n<p>1.\u4f7f\u7528root\u6743\u9650\u4fee\u6539\/etc\/profile\u6587\u4ef6\uff0c\u589e\u52a0 history\u64cd\u4f5c\u65e5\u5fd7\u914d\u7f6e\uff0c\u5185\u5bb9\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p>export HISTTIMEFORMAT=&#8221;[%Y-%m-%d %H:%M:%S] [`who am i 2&gt;\/dev\/null|awk &#8216;{print $NF}&#8217;|sed -e &#8216;s\/[()]\/\/g&#8217;`]&#8221;<\/p>\n\n\n\n<p>export PROMPT_COMMAND=&#8217;\\<\/p>\n\n\n\n<p>if [ -z &#8220;$OLD_PWD&#8221; ];then<\/p>\n\n\n\n<p>export OLD_PWD=$PWD;<\/p>\n\n\n\n<p>fi;<\/p>\n\n\n\n<p>if [ ! -z &#8220;$LAST_CMD&#8221; ] &amp;&amp; [ &#8220;$(history 1)&#8221; != &#8220;$LAST_CMD&#8221; ];then<\/p>\n\n\n\n<p>logger -t `whoami`_shell_cmd &#8220;[$OLD_PWD]$(history 1)&#8221;;<\/p>\n\n\n\n<p>fi;<\/p>\n\n\n\n<p>export LAST_CMD=&#8221;$(history 1)&#8221;;<\/p>\n\n\n\n<p>export OLD_PWD=$PWD;&#8217;<\/p>\n\n\n\n<p>2.\u6267\u884c\u547d\u4ee4\uff0c\u4f7f\u914d\u7f6e\u5185\u5bb9\u7acb\u5373\u751f\u6548<\/p>\n\n\n\n<p>source&nbsp;\/etc\/profile <\/p>\n\n\n\n<p>3.\u914d\u7f6e\u5b8c\u6210\u540e\u91cd\u65b0\u542f\u52a8rsyslog\u670d\u52a1<\/p>\n\n\n\n<p>service rsyslog restart<\/p>\n\n\n\n<p>4.\u65e5\u5fd7\u8bb0\u5f55\u6587\u4ef6\u53ca\u65e5\u5fd7\u683c\u5f0f<\/p>\n\n\n\n<p>logger\u547d\u4ee4\u9ed8\u8ba4\u7684\u65e5\u5fd7\u4fdd\u5b58\u5728 \/var\/log\/messages\u4e2d\u3002<\/p>\n\n\n\n<p>\u65e5\u5fd7\u683c\u5f0f\u5982\u4e0b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"718\" height=\"336\" src=\"http:\/\/www.betterit360.com\/wp-content\/uploads\/2019\/11\/Linux-history\u64cd\u4f5c\u65e5\u5fd7\u914d\u7f6e.png\" alt=\"\" class=\"wp-image-56\"\/><\/figure>\n\n\n\n<p>\u5982\u67e5\u770b\u793a\u4f8b\u56fe\u4e2duser1\u76f8\u5173\u64cd\u4f5c\u547d\u4ee4\uff0c\u53ef\u6267\u884c\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>grep &#8216;user1_shell_cmd&#8217; \/var\/log\/messages<\/p>\n","protected":false},"excerpt":{"rendered":"<p>History\u8bb0\u5f55\u4e86\u7528\u6237\u64cd\u4f5c\u547d\u4ee4\uff0c\u4f46\u6ca1\u6709\u8bb0\u5f55\u6765\u6e90ip\u5730\u5740\u3001\u64cd\u4f5c\u7528\u6237\u3001\u64cd\u4f5c\u65f6\u95f4\u7b49\uff0c\u4e14\u7528\u6237\u53ef\u4ee5\u6e05\u7a7aHistory\u8bb0 &hellip; <a href=\"http:\/\/www.betterit360.com\/?p=51\" class=\"more-link\">\u7ee7\u7eed\u9605\u8bfb<span class=\"screen-reader-text\">\u201cLinux History\u64cd\u4f5c\u65e5\u5fd7\u914d\u7f6e\u201d<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"http:\/\/www.betterit360.com\/index.php?rest_route=\/wp\/v2\/posts\/51"}],"collection":[{"href":"http:\/\/www.betterit360.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.betterit360.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.betterit360.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.betterit360.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=51"}],"version-history":[{"count":0,"href":"http:\/\/www.betterit360.com\/index.php?rest_route=\/wp\/v2\/posts\/51\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.betterit360.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=51"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.betterit360.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=51"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.betterit360.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=51"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}