Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

user logon acttivities with dates and terminals

Status
Not open for further replies.

promise1

IS-IT--Management
Sep 3, 2000
46
0
0
NG
hi !
i would like to get all user logon activities with the dates and terminals respectivel.

The history and .sh_history alternatives do not show the time and terminal of respective activities.

This is required for my audit department

Promise
 
promise,

cd into /var/adm

do

who wtmp

This will list all users who have logged into the system with times and dates from the last time the file was cleared down. Either pipe it to more or lp if you wish.

Cheers

PSD
IBM Certified Specialist - AIX V4.3 Systems Support
IBM Certified Specialist - AIX V4 HACMP
 
Not sure but I think Promise is after a log of all user activity (keystrokes, commands included)? Difficult one if you want to avoid very big files. However, a combination of PSD's suggestion and .sh_history might give an idea, if the latter is copied to an archive area for each user on a nightly basis. Auditors eh? Who needs 'em? ;-)
 
Are the auditors......looking for auditing or accounting for your machine?
See below to set up and info on............ PSD is right though who wtmp will give you a list of who and when...as well as checking /etc/security/failedlogin...for hackers on a particular port..... who /etc/security/failedlogin


accounting:

general accounting info

This wont tell you what commands they execute though....like Ken says...I guess it depends on what you are trying to capture?

Be aware that all of these create large files that need to be watched for size....and preened....
 
hi all thanks for your speedy responce. As you guessed right i would like to know the following for "previous" logins:

userid
time
login terminals
activities undertaken ( del , rcp etc)

cheers
Promise
 
Promise,

Well this is not easy the wtmp file will tell you terminal, user and time information but nothing breaks down user logins in terms of commands that have been run. Look at executing the script command when someone logs in, you could set up a simple script to log the user, time and tty and then use script to record the keystrokes, beware though the files will be very large. Or you could copy the .sh_history file to a new location relfecting the time, date e.t.c.

Cheers





PSD
IBM Certified Specialist - AIX V4.3 Systems Support
IBM Certified Specialist - AIX V4 HACMP
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top