16-2 Flashcards
contains various events logged by applications or programs
application log
this log contains events logged by Windows system components
system log
this log is used to store events collected from remote computers
forward events log
this log is used to store events from a single application or component rather than events that might have a systemwide impact
applications and services logs
linux log that contains failed user logins
/var/log/faillog
this linux log file is used for messages from the OS kernel
/var/log/kern.log
this linux log is the printer log and can give you a record of any items that have been printed from this machine
/var/log/lpr.log
this linux is themail server log and can be very useful in any computer crime investigation
/var/log/mail
this linux log records activities related to the SQL database server and will usually be of less interest to a computer crime investigation
/var/log/mysql.*
this linux log is for the apache web server, and will show related activity
/var/log/apache2/*
this linux log will show activity for lighttpd/*
/var/log/lighttpd/*
this linux log records application crashes
/var/log/apport.log
this linux log contains user activity logs
/var/log/user.log
a free tool used ot recover windows files
disk digger