Why not just write a copy of /etc/passwd to a file at regular intervals. Not foolproof however. Another possibility would be to monitor smit.log for the appropriate entries.
Monitoring smit.log is not enough. On one hand you might not be sure which smit.log is to be monitored (if not only root user is allowed to create users). On the other hand you can use command line to do the same (mkuser/pwdadm or even vi) which do not leave entries in smit.log.
Thus I think monitoring passwd is a better idea. How often does the user list change?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.