Skip to main content

Sudoers Configuration (stop and start services)

So you want to allow other users to stop and start some of the services. From the linux point of view you can do this by using sudo.

Change ".bash profile" file contents of the user so that "service" and "chkconfig" commands will be in the PATH environment variable. "/sbin" folder must be included.

# .bash_profile
# Get the aliases and functions
if [ -f ~/.bashrc ]; then
        . ~/.bashrc
fi
# User specific environment and startup programs
PATH=$PATH:$HOME/bin:/sbin
export PATH



Change the "/etc/sudoers" file using "visudo" command like:

Host_Alias       OPNETS = <ip address of the server>
User_Alias       OPERATORS = <username>, root
Runas_Alias     OP = <username>, root
Cmnd_Alias      SERVICES = /sbin/service, /sbin/chkconfig

Defaults        logfile=/var/log/sudo.log
Defaults       lecture_file=/etc/mylecturefile

OPERATORS       OPNETS=(OP) NOPASSWD: SERVICES

"logfile" holds logs that contains which commands executed with the user at which time from which terminal console and from which ip address etc. "NOPASSWD" is required for using sudo without password.

After these changes the operator user can be list services and can change status of the services.

# sudo chkconfig --list
# sudo service sendmail stop

Comments

Popular posts from this blog

Find and replace with sed command in Linux

Find and replace feature is always handy. It can turn into a torture when it comes to change or delete a simple constant string in a text file. There is a handy tool in linux for doing these kind of tihngs. Actually sed is not a text editor but it is used outside of the text file to make changes.

Sending Jboss Server Logs to Logstash Using Filebeat with Multiline Support

In addition to sending system logs to logstash, it is possible to add a prospector section to the filebeat.yml for jboss server logs. Sometimes jboss server.log has single events made up from several lines of messages. In such cases Filebeat should be configured for a multiline prospector.
Filebeat takes lines do not start with a date pattern (look at pattern in the multiline section "^[[:digit:]]{4}-[[:digit:]]{2}-[[:digit:]]{2}" and negate section is set to true) and combines them with the previous line that starts with a date pattern.

server.log file excerpt where DatePattern: yyyy-MM-dd-HH and ConversionPattern: %d %-5p [%c] %m%n
Logstash filter: