Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

log commmands entered by users?

Status
Not open for further replies.

jpn1

Technical User
Jul 9, 2007
34
US
We are having weird things, well corupted index's on a customers system. We have seen this in the past when a customer uses kill -9 to stop certain processes.

They say no one does this. I know I can log in as a particular user and look through that users history, but on a system with 60+ users. Could take some time.

Maybe I can collect all the history files and then write a parser that would find certain commands.

I am wondering if there is a log file that collects when these commands are issued, or if one can be configured.
 
You might take a look at AIX audit. I'm not sure if it can do this or not...but it can monitor some unique stuff
 
I'm not familar with AIX audit, is this 3rd party software?
 
Nope, it's part of AIX. I run it on 5.2 and 5.3 for some very basic stuff (user and group changes). It's creates a report of who changed what.

Just google it.
 
Actually...check out:


look at adobe page (45 out of 200). The page actually says it's "Chapter 2. Auditing on AIX (page) 31"

or search for "kill" in this pdf. It's exactly what you're looking for. It's a bit involved, I guess it depends on how bad you want to know the answer.
 
WOW thanks, I've setup advanced auditing and can now audit when users use the kill command.
Exactly what I needed. Thanks for the direction.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top