05-08-2006
here...
The availability of details is depended on the syslog's settings, but in any case you can do following:
1. Get the boot time. You can get it by couple of ways, as you can type "uptime" commands and count back for how long it was on, or you can go to
/var/log and see the boot.log file, or in the same directory see "messages" file and look for "syslog started" time stamp.
2. type "last" command and see who were the uses logged in at the time when system had been rebooted
3. See these users shell history files in ~username/.bash_history for su or sudo commands.
All the aforesaid makes sense ONLY if you have proper access to root account and no one but root user knows the root's password. If you guys share the root password it is almost impossible to find who had rebooted the system. The only chance if you had systlog set to record network events. You can see in /var/log, messages and security logs for connections with a time-stamp kept alive around the reboot. Given your DHCP is long leasing or static IPs were used/or logs entries resolve DNS you can get the list of suspects. Then you proceed to step 3.
Have in mind that if someone INTENTIONALLY reboot the system and had complete root access and posses some skills, it is not only impossible to track, he/she may forge logs in any desirable way.
DO NOT SHARE ROOT ACCESS! USE "SUDO" TO PROTECT ROOT ACCOUNT!
9 More Discussions You Might Find Interesting
1. Solaris
Hi,
how can i know who has rebooted the server? even last command is not displaying the user, wheather any way to track the user. (2 Replies)
Discussion started by: manoj.solaris
2 Replies
2. HP-UX
Hi ,
Plz some one can help me ...
How can we know that the server was rebooted by which user in hp unix and linux.
Regards
Venkata Jeevan (1 Reply)
Discussion started by: jeevanbv
1 Replies
3. AIX
Hi,
I want to know how to find out which user has rebooted the server? I have used last command but it is not giving username though it is showing below output
reboot --------------- date
Regards,
Manoj (5 Replies)
Discussion started by: manoj.solaris
5 Replies
4. Solaris
In Windows we can check the event viewer for entries 6005,6006,6009 to confirm the system down times, as in when it got down and when it came back up. Is there some similar log files in Solaris/RHEL that I can check the timings and who or what caused the system reboot. I am an absolute newbie. Need... (4 Replies)
Discussion started by: lubu
4 Replies
5. Red Hat
I am trying to figure out what might causing Production server unexpectedly reboot during last few months ..
Is auto reboot is set , I can check it is not set during the kernel panic but are they any other parameters which I am missing .
-bash-2.05b$ uname -a
Linux PD1011... (4 Replies)
Discussion started by: dba1981
4 Replies
6. Shell Programming and Scripting
We are using linux server. We have below script running on the crontab and it send the alert if the cpu usage is above 90%.
My question is, the below script tells the CPU usage for one CPU or all CPU in the server?
sar 1 1 | sed '$!d' | awk '{printf("%d", $8)}' > $SAR_LOG
Please let me... (4 Replies)
Discussion started by: govindts
4 Replies
7. Red Hat
Hi
One of our server is showing the uptime 0hr 5mints
there is no log in /var/log/messages
there is no log in command "last"
kernel version is 2.4.9 (RH2.1 AS)
What could be the reason for this. is this issue is related to uptime counter reached max
how to verify this.
Best Regards
KVK (4 Replies)
Discussion started by: venikathir
4 Replies
8. Red Hat
Hi,
Yesterday one of Red Hat Server 4.2 got rebooted.
I have checked /var/log/messages, but does not find out any serious issue related to peformance / hardware issue.
how to find out why server was rebooted? (1 Reply)
Discussion started by: manoj.solaris
1 Replies
9. UNIX for Dummies Questions & Answers
I have been mounting a directory to share with a windows pc. If i reboot the AIX box the mount goes away. How can i make the mount permanent? Here is the command I use to make the mount
exportfs -i -o root=<servername> /path (1 Reply)
Discussion started by: fierfek
1 Replies
LAST,LASTB(1) Linux System Administrator's Manual LAST,LASTB(1)
NAME
last, lastb - show listing of last logged in users
SYNOPSIS
last [-R] [-num] [ -n num ] [-adiox] [ -f file ] [ -t YYYYMMDDHHMMSS ] [name...] [tty...]
lastb [-R] [-num] [ -n num ] [ -f file ] [ -t YYYYMMDDHHMMSS ] [-adiox] [name...] [tty...]
DESCRIPTION
Last searches back through the file /var/log/wtmp (or the file designated by the -f flag) and displays a list of all users logged in (and
out) since that file was created. Names of users and tty's can be given, in which case last will show only those entries matching the
arguments. Names of ttys can be abbreviated, thus last 0 is the same as last tty0.
When last catches a SIGINT signal (generated by the interrupt key, usually control-C) or a SIGQUIT signal (generated by the quit key, usu-
ally control-), last will show how far it has searched through the file; in the case of the SIGINT signal last will then terminate.
The pseudo user reboot logs in each time the system is rebooted. Thus last reboot will show a log of all reboots since the log file was
created.
Lastb is the same as last, except that by default it shows a log of the file /var/log/btmp, which contains all the bad login attempts.
OPTIONS
-num This is a count telling last how many lines to show.
-n num The same.
-t YYYYMMDDHHMMSS
Display the state of logins as of the specified time. This is useful, e.g., to determine easily who was logged in at a particular
time -- specify that time with -t and look for "still logged in".
-R Suppresses the display of the hostname field.
-a Display the hostname in the last column. Useful in combination with the next flag.
-d For non-local logins, Linux stores not only the host name of the remote host but its IP number as well. This option translates the
IP number back into a hostname.
-i This option is like -d in that it displays the IP number of the remote host, but it displays the IP number in numbers-and-dots nota-
tion.
-o Read an old-type wtmp file (written by linux-libc5 applications).
-x Display the system shutdown entries and run level changes.
NOTES
The files wtmp and btmp might not be found. The system only logs information in these files if they are present. This is a local configura-
tion issue. If you want the files to be used, they can be created with a simple touch(1) command (for example, touch /var/log/wtmp).
FILES
/var/log/wtmp
/var/log/btmp
AUTHOR
Miquel van Smoorenburg, miquels@cistron.nl
SEE ALSO
shutdown(8), login(1), init(8)
Jul 29, 1999 LAST,LASTB(1)