The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
How can we know that the server was rebooted by which user in hp unix jeevanbv HP-UX 1 05-28-2008 09:02 AM
rebooted alone murad.jaber SUN Solaris 3 10-22-2007 07:05 AM
server rebooted by user manoj.solaris SUN Solaris 2 10-08-2007 12:36 PM
how can I know when system last rebooted? nokia1100 Shell Programming and Scripting 3 04-06-2007 07:47 PM
Sun Machine Rebooted DPAI UNIX for Dummies Questions & Answers 6 09-05-2001 01:56 PM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-08-2006
Registered User
 

Join Date: Sep 2001
Posts: 67
Stumble this Post!
How to identify who rebooted the linux server

Hi All,

Since server is located at remote place so how to identify which user rebooted the server. Is there any way to identify the user.

Thanks in advance,

Reg,
Bache Gowda
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 05-08-2006
Registered User
 

Join Date: Mar 2006
Posts: 106
Stumble this Post!
here...

The availability of details is depended on the syslog's settings, but in any case you can do following:

1. Get the boot time. You can get it by couple of ways, as you can type "uptime" commands and count back for how long it was on, or you can go to
/var/log and see the boot.log file, or in the same directory see "messages" file and look for "syslog started" time stamp.

2. type "last" command and see who were the uses logged in at the time when system had been rebooted

3. See these users shell history files in ~username/.bash_history for su or sudo commands.

All the aforesaid makes sense ONLY if you have proper access to root account and no one but root user knows the root's password. If you guys share the root password it is almost impossible to find who had rebooted the system. The only chance if you had systlog set to record network events. You can see in /var/log, messages and security logs for connections with a time-stamp kept alive around the reboot. Given your DHCP is long leasing or static IPs were used/or logs entries resolve DNS you can get the list of suspects. Then you proceed to step 3.

Have in mind that if someone INTENTIONALLY reboot the system and had complete root access and posses some skills, it is not only impossible to track, he/she may forge logs in any desirable way.

DO NOT SHARE ROOT ACCESS! USE "SUDO" TO PROTECT ROOT ACCOUNT!
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 04:26 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0