The Log File Bloat
Ubuntu utilizes a robust logging system to record system events, with security-related information saved to a file located at /var/log/auth.log. This file is critical for auditing SSH logins and tracking sudo command execution. However, if you are running automated scripts via cron jobs that require root privileges, or if you have a monitoring daemon pinging your system continuously, Ubuntu will write a new entry to the auth.log file every single time that background task executes. Over weeks or months, this can generate millions of lines of “spam,” inflating the log file to gigabytes in size and making it impossible for a human administrator to find actual security threats hidden among the automated noise.
Filtering the Daemon Activity
To stop this specific spam while retaining legitimate login records, you must configure the PAM (Pluggable Authentication Modules) system to silently ignore authentication requests generated by the cron daemon.
Open a terminal window and edit the cron PAM configuration file by typing: sudo nano /etc/pam.d/cron and pressing Enter. Look through the file for the line that reads: session required pam_loginuid.so. This is the module responsible for writing the session start/stop messages to your auth.log. You do not want to delete this line; instead, you must instruct it to be quiet. Change the line so it reads exactly: session [success=1 default=ignore] pam_loginuid.so. Press Ctrl+O to save the file, then Ctrl+X to exit. Finally, restart the cron service by typing sudo systemctl restart cron. Automated scripts will now execute silently without polluting your security logs.