10-08-2007
The pty that gave the command should be in the system logs, it is just a matter of tallying that with the output from last to see who had that terminal allocated.
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
Hi All,
Since server is located at remote place so how to identify which user rebooted the server. Is there any way to identify the user.
Thanks in advance,
Reg,
Bache Gowda (1 Reply)
Discussion started by: bache_gowda
1 Replies
2. HP-UX
Hi ,
Plz some one can help me ...
How can we know that the server was rebooted by which user in hp unix and linux.
Regards
Venkata Jeevan (1 Reply)
Discussion started by: jeevanbv
1 Replies
3. AIX
Hi,
I want to know how to find out which user has rebooted the server? I have used last command but it is not giving username though it is showing below output
reboot --------------- date
Regards,
Manoj (5 Replies)
Discussion started by: manoj.solaris
5 Replies
4. Linux
supermicro(dual core) server getting rebooted after "decompressing the kernel;booting the kernel" message comes.
I tried giving acpi=off to the kernel command line but same problem.It shows everything ok and no problem with memory and processors and power supplies.Wt could be the reason?
It has... (1 Reply)
Discussion started by: pankajd
1 Replies
5. Solaris
In Windows we can check the event viewer for entries 6005,6006,6009 to confirm the system down times, as in when it got down and when it came back up. Is there some similar log files in Solaris/RHEL that I can check the timings and who or what caused the system reboot. I am an absolute newbie. Need... (4 Replies)
Discussion started by: lubu
4 Replies
6. Red Hat
I am trying to figure out what might causing Production server unexpectedly reboot during last few months ..
Is auto reboot is set , I can check it is not set during the kernel panic but are they any other parameters which I am missing .
-bash-2.05b$ uname -a
Linux PD1011... (4 Replies)
Discussion started by: dba1981
4 Replies
7. Red Hat
Hi
One of our server is showing the uptime 0hr 5mints
there is no log in /var/log/messages
there is no log in command "last"
kernel version is 2.4.9 (RH2.1 AS)
What could be the reason for this. is this issue is related to uptime counter reached max
how to verify this.
Best Regards
KVK (4 Replies)
Discussion started by: venikathir
4 Replies
8. Red Hat
Hi,
Yesterday one of Red Hat Server 4.2 got rebooted.
I have checked /var/log/messages, but does not find out any serious issue related to peformance / hardware issue.
how to find out why server was rebooted? (1 Reply)
Discussion started by: manoj.solaris
1 Replies
9. UNIX for Dummies Questions & Answers
I have been mounting a directory to share with a windows pc. If i reboot the AIX box the mount goes away. How can i make the mount permanent? Here is the command I use to make the mount
exportfs -i -o root=<servername> /path (1 Reply)
Discussion started by: fierfek
1 Replies
10. Shell Programming and Scripting
Can someone help in writing some script through which I can transfer file (scp) from root user in abc server to crt user in hfg server and can give the crt user password in script itself so that it doesn't prompt me every time for password (4 Replies)
Discussion started by: Moon1234
4 Replies
LEARN ABOUT DEBIAN
ttysnoop
TTYSNOOP(8) BSD System Manager's Manual TTYSNOOP(8)
NAME
ttysnoop -- snoop on a user's tty
SYNOPSIS
ttysnoop [pty]
ttysnoops
DESCRIPTION
The ttysnoop / ttysnoops client-server combo can be used to snoop (watch) on a user's login tty. The server (ttysnoops) is usually started
by getty(8) or telnetd(8) and reads the file /etc/snooptab to find out which tty's should be cloned and which programs to run on them (usu-
ally /bin/login). A tty may be snooped through a pre-determined (ie. fixed) device, or through a dynamically allocated pseudo-tty (pty).
This is also specified in the /etc/snooptab file. To connect to the pty, the client ttysnoop should be used. The available pseudo terminals
pty are present as sockets in the directory /var/spool/ttysnoop/.
Format of /etc/snooptab
The /etc/snooptab file may contain comment lines (starting with a '#'), empty lines, or entries for tty's that should be snooped upon. The
format of such an entry is as follows:
tty snoop-device type program
where tty is the leaf-name of the tty that should be snooped upon (eg. ttyS2, not /dev/ttyS2) OR the wildcard '*', which matches ANY tty.
snoop-device is the device through which tty should be snooped (eg. /dev/tty8) OR the literal constant "socket". The latter is used to tell
ttysnoops that the snoop-device will be a dynamically allocated pty. type specifies the type of program that should be run, currently recog-
nized types are "init", "user" and "login" although the former two aren't really needed. Finally, program is the full pathname to the program
to run when ttysnoops has cloned tty onto snoop-device.
EXAMPLE
The following example /etc/snooptab file should illustrate the typical use of ttysnoop / ttysnoops:
#
# example /etc/snooptab
#
ttyS0 /dev/tty7 login /bin/login
ttyS1 /dev/tty8 login /bin/login
#
# the wildcard tty should always be the last one in the file
#
* socket login /bin/login
#
# example end
#
With the above example, whenever a user logs in on /dev/ttyS0 or /dev/ttyS1, either tty will be snooped through /dev/tty7 or /dev/tty8
respectively. Any other tty's will be snooped through a pty that will be allocated at the time of login. The system-administrator can then
run ttysnoop pty to snoop through the pty. Note that it is up to the system-administrator to setup getty and/or telnetd so that they execute
ttysnoops instead of /bin/login.
SEE ALSO
getty(8), telnetd(8)
FILES
/etc/snooptab
BUGS
The program is unable to do any terminal control-code translations for the original tty and the snoop-device. I doubt it will ever do this.
AUTHOR
Carl Declerck, carl@miskatonic.inbe.net
BSD
August 8 1994 BSD