10-13-2003
Hi Jennifer,
There is a different way to find out who actualy logged into the system.
"last" displays this to you.
"last -R" Also shows you where they came from.
"lastb" shows you who tried, but where refused.
If you want this in a file just redirect the output :
"last -R 1>/tmp/lastlogin"
"man last" if you need more info on the command.
Regs David
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
hi all.....
i want to know how to log the details when logging into a server using SFTP......in FTP i used something like (ftp -uv<xxx.srp>>log_file.log) where the details will be logged to log_file...is there any options for doing the same in SFTP....i wanted to display the details abt... (4 Replies)
Discussion started by: santy
4 Replies
2. Solaris
Dear All,
I want to enable the tracing for a user and logging all things he do in a log file..........
Thaaanks (2 Replies)
Discussion started by: adel8483
2 Replies
3. HP-UX
Hi,
I wonder if anyone is able to assist me.
I have a HP UX server and some HP UX workstations that has been migrated from another network. I have changed the IP Addresses and everything seems to be working fine.
However, the users are complaining that they are unable to login to the UX... (1 Reply)
Discussion started by: michaelgim
1 Replies
4. UNIX for Dummies Questions & Answers
Hi,
I am trying authenticate ssh users login using third party server (radius) instead of local system authentication.
I have modified my /etc/pam.d/sshd with required server auth configuration and able to authenticate user using radius server and the user is able to ssh into this linux... (2 Replies)
Discussion started by: dhandapanik
2 Replies
5. AIX
I want to know how I can turn off and turn on login logging. We have a server that appears to have stopped logging user logins. Running the who command shows nothing and the last command shows no logins for a month. The var/adm/wtmp file isn't full and there is plenty of space in the var file... (2 Replies)
Discussion started by: daveisme
2 Replies
6. UNIX for Dummies Questions & Answers
I have created a linux machine and installed some softwares on it with root user privileges . I used to login with root user credentials for doing the various task.
Later i have realise that this is not the best practice to follow and there should be a new user with less privileges to be created... (1 Reply)
Discussion started by: pinga123
1 Replies
7. UNIX for Advanced & Expert Users
Hello,
I am using a Linux server (Ubuntu 11.04 Server) to host some files and a code repository. Because we are using ssh + svn to connect to the repository, our users have normal ssh access.
What I would like to do is log their user sessions so that I have an audit trail in the event that... (2 Replies)
Discussion started by: chrisb1609
2 Replies
8. UNIX for Dummies Questions & Answers
Hi - I want to log commands typed by oraapps user with time into some log file on runtime.
HISTTIMEFORMAT="%d/%m/%y %T " works but any one with oraapps user can delete the history.
OS : RHEl 5.6
Any help is appreciated. (5 Replies)
Discussion started by: oraclermanpt
5 Replies
9. Shell Programming and Scripting
Hi,
I have several engineers logging into servers with the same system username and passwords eg root. I was thinking about adding a script to bashrc where a user is forced upon login to enter their name and once that has executed there history is logged/redirected to a log file somewhere. I... (10 Replies)
Discussion started by: maxwellhouse
10 Replies
10. Linux
When unlocking a Linux server's console there's no event indicating successful logging
Is there a way I can fix this ?
I have the following in my rsyslog.conf
auth.info /var/log/secure
authpriv.info /var/log/secure (1 Reply)
Discussion started by: walterthered
1 Replies
LAST, LASTB(1) User Commands LAST, LASTB(1)
NAME
last, lastb - show a listing of last logged in users
SYNOPSIS
last [options] [username...] [tty...]
lastb [options] [username...] [tty...]
DESCRIPTION
last searches back through the /var/log/wtmp file (or the file designated by the -f option) and displays a list of all users logged in (and
out) since that file was created. One or more usernames and/or ttys can be given, in which case last will show only the entries matching
those arguments. Names of ttys can be abbreviated, thus last 0 is the same as last tty0.
When catching a SIGINT signal (generated by the interrupt key, usually control-C) or a SIGQUIT signal, last will show how far it has
searched through the file; in the case of the SIGINT signal last will then terminate.
The pseudo user reboot logs in each time the system is rebooted. Thus last reboot will show a log of all the reboots since the log file
was created.
lastb is the same as last, except that by default it shows a log of the /var/log/btmp file, which contains all the bad login attempts.
OPTIONS
-a, --hostlast
Display the hostname in the last column. Useful in combination with the --dns option.
-d, --dns
For non-local logins, Linux stores not only the host name of the remote host, but its IP number as well. This option translates the
IP number back into a hostname.
-f, --file file
Tell last to use a specific file instead of /var/log/wtmp. The --file option can be given multiple times, and all of the specified
files will be processed.
-F, --fulltimes
Print full login and logout times and dates.
-i, --ip
Like --dns , but displays the host's IP number instead of the name.
-number
-n, --limit number
Tell last how many lines to show.
-p, --present time
Display the users who were present at the specified time. This is like using the options --since and --until together with the same
time.
-R, --nohostname
Suppresses the display of the hostname field.
-s, --since time
Display the state of logins since the specified time. This is useful, e.g., to easily determine who was logged in at a particular
time. The option is often combined with --until.
-t, --until time
Display the state of logins until the specified time.
--time-format format
Define the output timestamp format to be one of notime, short, full, or iso. The notime variant will not print any timestamps at
all, short is the default, and full is the same as the --fulltimes option. The iso variant will display the timestamp in ISO-8601
format. The ISO format contains timezone information, making it preferable when printouts are investigated outside of the system.
-w, --fullnames
Display full user names and domain names in the output.
-x, --system
Display the system shutdown entries and run level changes.
TIME FORMATS
The options that take the time argument understand the following formats:
YYYYMMDDhhmmss
YYYY-MM-DD hh:mm:ss
YYYY-MM-DD hh:mm (seconds will be set to 00)
YYYY-MM-DD (time will be set to 00:00:00)
hh:mm:ss (date will be set to today)
hh:mm (date will be set to today, seconds to 00)
now
yesterday (time is set to 00:00:00)
today (time is set to 00:00:00)
tomorrow (time is set to 00:00:00)
+5min
-5days
NOTES
The files wtmp and btmp might not be found. The system only logs information in these files if they are present. This is a local configu-
ration issue. If you want the files to be used, they can be created with a simple touch(1) command (for example, touch /var/log/wtmp).
FILES
/var/log/wtmp
/var/log/btmp
AUTHOR
Miquel van Smoorenburg <miquels@cistron.nl>
AVAILABILITY
The last command is part of the util-linux package and is available from Linux Kernel Archive <https://www.kernel.org/pub/linux/utils/util-
linux/>.
SEE ALSO
login(1), wtmp(5), init(8), shutdown(8)
util-linux October 2013 LAST, LASTB(1)