<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to purge btmp&amp;amp;wtmp under /var/adm? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469247#M211388</link>
    <description>hi,&lt;BR /&gt;&lt;BR /&gt;as Indira mentioned above, unless you want to keep the information contained in these files, you may trim them to zero.&lt;BR /&gt;&lt;BR /&gt;you can also do:&lt;BR /&gt;cat /dev/null &amp;gt; /var/adm/btmp&lt;BR /&gt;&lt;BR /&gt;hope this helps!&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;yogeeraj</description>
    <pubDate>Mon, 24 Jan 2005 03:13:08 GMT</pubDate>
    <dc:creator>Yogeeraj_1</dc:creator>
    <dc:date>2005-01-24T03:13:08Z</dc:date>
    <item>
      <title>How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469244#M211385</link>
      <description>Can we do '&amp;gt;btmp'?</description>
      <pubDate>Mon, 24 Jan 2005 01:40:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469244#M211385</guid>
      <dc:creator>ericfjchen</dc:creator>
      <dc:date>2005-01-24T01:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469245#M211386</link>
      <description>It is HP-UX 10.20.</description>
      <pubDate>Mon, 24 Jan 2005 01:41:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469245#M211386</guid>
      <dc:creator>ericfjchen</dc:creator>
      <dc:date>2005-01-24T01:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469246#M211387</link>
      <description>Hi Eric,&lt;BR /&gt;&lt;BR /&gt;File btmp contains bad login entries for each invalid logon attempt. File wtmp contains a record of all logins and logouts.&lt;BR /&gt;&lt;BR /&gt;wtmp and btmp tend to grow without bound, and should be checked regularly.  Information that is no longer useful should be removed periodically to prevent it from becoming too large. &lt;BR /&gt;&lt;BR /&gt;You can use sam to trim the logs.  Sam--Ã&amp;nbsp;Routine Tasks---Ã&amp;nbsp;System Log Files-----select /var/adm/wtmp and /var/admbtmp then from Action menu select trim to zero.&lt;BR /&gt;&lt;BR /&gt;Note:- If these files are removed, record-keeping is turned off. Before triming the logs if you want to make a record of the incorrect / bad logins you can use fwtmp which reads from the wtmp file converting binary records to formatted ASCII records. &lt;BR /&gt;&lt;BR /&gt;Indir</description>
      <pubDate>Mon, 24 Jan 2005 03:00:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469246#M211387</guid>
      <dc:creator>Indira Aramandla</dc:creator>
      <dc:date>2005-01-24T03:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469247#M211388</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;as Indira mentioned above, unless you want to keep the information contained in these files, you may trim them to zero.&lt;BR /&gt;&lt;BR /&gt;you can also do:&lt;BR /&gt;cat /dev/null &amp;gt; /var/adm/btmp&lt;BR /&gt;&lt;BR /&gt;hope this helps!&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;yogeeraj</description>
      <pubDate>Mon, 24 Jan 2005 03:13:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469247#M211388</guid>
      <dc:creator>Yogeeraj_1</dc:creator>
      <dc:date>2005-01-24T03:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469248#M211389</link>
      <description>"man runacct" and "man 1M acct" should be a good start. Rather than losing accounting information, you can log it.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jan 2005 03:22:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469248#M211389</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2005-01-24T03:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469249#M211390</link>
      <description>Hey,&lt;BR /&gt;&lt;BR /&gt;When the file i becomming to big, I usally make a bakup of the file and then:&lt;BR /&gt;/usr/sbin/acct/fwtmp &amp;lt; /var/adm/btmp &amp;gt; /var/tmp/btmp.tmp&lt;BR /&gt;tail -n -2048 /var/tmp/btmp.tmp &amp;gt;/var/tmp/btmp.tmp1&lt;BR /&gt;/usr/sbin/acct/fwtmp -ic &amp;lt; /var/tmp/btmp.tmp1 &amp;gt; /var/adm/btmp&lt;BR /&gt;&lt;BR /&gt;This will keep the most resent data. The commad lastb is the one using btmp, often you are able to see password of other users in the file, but thats another story, but make sure only root is able to read/write the file:&lt;BR /&gt;-rw-------   1 root       other        1024 Dec 30 14:36 btmp</description>
      <pubDate>Mon, 24 Jan 2005 03:49:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469249#M211390</guid>
      <dc:creator>Jannik</dc:creator>
      <dc:date>2005-01-24T03:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469250#M211391</link>
      <description>The safest thing to do is run accounting, which will re-create these files.  This includes fixing permissions and corruptions that can occur with these files.&lt;BR /&gt;&lt;BR /&gt;It's actually a great practice, though under utilized, to run system accounting.  Read the man pages for runacct for more information.&lt;BR /&gt;&lt;BR /&gt;Basics:&lt;BR /&gt;/usr/sbin/acct/turnacct on&lt;BR /&gt;&lt;BR /&gt;vi /etc/acct/holidays&lt;BR /&gt;# Make sure the year is correct&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/acct/runacct&lt;BR /&gt;&lt;BR /&gt;If you do not plan to maintain accounting then run:&lt;BR /&gt;/usr/sbin/acct/turnacct off&lt;BR /&gt;&lt;BR /&gt;If you plan to maintain system accounting, vi /etc/rc.config.d/acct and set the variable to 1 so that accounting starts at system boot.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Shannon</description>
      <pubDate>Mon, 24 Jan 2005 11:39:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469250#M211391</guid>
      <dc:creator>Shannon Petry</dc:creator>
      <dc:date>2005-01-24T11:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469251#M211392</link>
      <description>Sure - you can do a &lt;BR /&gt;&lt;BR /&gt;&amp;gt; btmp&lt;BR /&gt;&lt;BR /&gt;or cp /dev/null &amp;gt; btmp&lt;BR /&gt;&lt;BR /&gt;Or use sam&lt;BR /&gt;&lt;BR /&gt;Tip:&lt;BR /&gt;Want to know what SAM does?&lt;BR /&gt;Run '/usr/sam/bin/samlog_viewer' and see what commands SAM ran. &lt;BR /&gt;Or you can 'view' /var/sam/log/samlog to search for yourself.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jan 2005 14:56:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469251#M211392</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2005-01-24T14:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to purge btmp&amp;wtmp under /var/adm?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469252#M211393</link>
      <description>Another thing you can do is, install logrotate:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://hpux.ee.ualberta.ca/hppd/hpux/Sysadmin/logrotate-2.5/" target="_blank"&gt;http://hpux.ee.ualberta.ca/hppd/hpux/Sysadmin/logrotate-2.5/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;# cat logrotate.conf&lt;BR /&gt;# see "man logrotate" for details&lt;BR /&gt;# rotate log files weekly&lt;BR /&gt;weekly&lt;BR /&gt;&lt;BR /&gt;# keep 4 weeks worth of backlogs&lt;BR /&gt;rotate 5&lt;BR /&gt;&lt;BR /&gt;# create new (empty) log files after rotating old ones&lt;BR /&gt;create&lt;BR /&gt;&lt;BR /&gt;# uncomment this if you want your log files compressed&lt;BR /&gt;#compress&lt;BR /&gt;&lt;BR /&gt;# packages drop log rotation information into this directory&lt;BR /&gt;include /etc/logrotate.d&lt;BR /&gt;&lt;BR /&gt;# no packages own wtmp -- we'll rotate them here&lt;BR /&gt;/var/adm/wtmp {&lt;BR /&gt;    monthly&lt;BR /&gt;    create 0664 adm adm&lt;BR /&gt;    rotate 1&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff</description>
      <pubDate>Mon, 24 Jan 2005 14:59:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-purge-btmp-amp-wtmp-under-var-adm/m-p/3469252#M211393</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2005-01-24T14:59:42Z</dc:date>
    </item>
  </channel>
</rss>

