Hello,
I'm new to Unix I'm running an MIS on Unix and want some advice on how to monitor failed logins, and who's accessing it and when.
I found the command who -a /etc/security/failedlogin but got loads of information.
How do I get the output into a file, and how can I restrict the command to look within range of dates or a single date.
I also want to understand audit. I looked at the man page but it makes no sense to me.
I think that's enough for now!
I'm new to Unix I'm running an MIS on Unix and want some advice on how to monitor failed logins, and who's accessing it and when.
I found the command who -a /etc/security/failedlogin but got loads of information.
How do I get the output into a file, and how can I restrict the command to look within range of dates or a single date.
I also want to understand audit. I looked at the man page but it makes no sense to me.
I think that's enough for now!