【参考】OS にログインすれば journal ログは出る
10
# journalctl -f
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: USER_AUTH pid=9782 uid=0 auid=4294967295 ses=4294967295
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authenticationgrantors=pam_unix acct="root" exe="/usr/bin/login" hostname=ip-10-0-15-
250.ap-northeast-1.compute.internal addr=? terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: USER_ACCT pid=9782 uid=0 auid=4294967295 ses=4294967295
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting grantors=pam_unix acct="root" exe="/usr/bin/login" hostname=ip-10-0-15-
250.ap-northeast-1.compute.internal addr=? terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: CRED_ACQ pid=9782 uid=0 auid=4294967295 ses=4294967295
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_unix acct="root" exe="/usr/bin/login" hostname=ip-10-0-15-250.ap-
northeast-1.compute.internal addr=? terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: USER_ROLE_CHANGE pid=9782 uid=0 auid=0 ses=2
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-
context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/bin/login" hostname=ip-10-0-15-250.ap-northeast-1.compute.internal addr=?
terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal systemd[1]: Starting
[email protected] - Refresh policy routes for ens5...
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal systemd-logind[1405]: New session 2 of user root.
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal systemd[1]: Started session-2.scope - Session 2 of User root.
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal login[9782]: pam_unix(login:session): session opened for user root(uid=0) by (uid=0)
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal login[9782]: DIALUP AT ttyS0 BY root
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal login[9782]: ROOT LOGIN ON ttyS0
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: USER_START pid=9782 uid=0 auid=0 ses=2
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open
grantors=pam_selinux,pam_loginuid,pam_selinux,pam_namespace,pam_keyinit,pam_keyinit,pam_limits,pam_systemd,pam_unix,pam_umask,pam_lastlog
acct="root" exe="/usr/bin/login" hostname=ip-10-0-15-250.ap-northeast-1.compute.internal addr=? terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: CRED_REFR pid=9782 uid=0 auid=0 ses=2
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_unix acct="root" exe="/usr/bin/login" hostname=ip-10-0-15-250.ap-
northeast-1.compute.internal addr=? terminal=/dev/ttyS0 res=success'
May 25 15:36:03 ip-10-0-15-250.ap-northeast-1.compute.internal audit[9782]: USER_LOGIN pid=9782 uid=0 auid=0 ses=2
subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/bin/login" hostname=ip-10-0-15-250.ap-northeast-1.compute.internal addr=?
terminal=ttyS0 res=success'