<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event logs including info about system and users activities in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404378#M663370</link>
    <description>&amp;gt;I could not see the new records on a server after using "last -R -100". What might happen?&lt;BR /&gt;&lt;BR /&gt;Since last(1) reverses the order, which direction did you mean by "new records"?&lt;BR /&gt;Did you mean there are no entries for Apr 21 and later in time?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;After "last -R -20 -f /var/adm/wtmp" output, I see that the last record is "Apr 20". I couldn't see even the last record on the file by "last -R -100". And there are no new records on the file after that date.&lt;BR /&gt;&lt;BR /&gt;You're saying last(1) indicates nobody has logged on since Apr 20?&lt;BR /&gt;How big is the file?  It could have been corrupted on april 20?</description>
    <pubDate>Wed, 29 Apr 2009 14:30:24 GMT</pubDate>
    <dc:creator>Dennis Handly</dc:creator>
    <dc:date>2009-04-29T14:30:24Z</dc:date>
    <item>
      <title>Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404370#M663362</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I want to know about when a user logged in system, Which IP was used by user, What kind of commands were used by user, Which processes were run by user etc.&lt;BR /&gt;&lt;BR /&gt;So How can reach this information, where are the log files including those information?&lt;BR /&gt;&lt;BR /&gt;Can anybody show me the related log file path?&lt;BR /&gt;Thanks,&lt;BR /&gt;Ali Kemal.&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Apr 2009 21:45:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404370#M663362</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-04-20T21:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404371#M663363</link>
      <description>For login/logouts and IP, you can use last(1).&lt;BR /&gt;&lt;BR /&gt;For the commands and processes, you must enable auditing.&lt;BR /&gt;You might be able to look at some of their shell history file but that's not accurate.</description>
      <pubDate>Tue, 21 Apr 2009 03:10:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404371#M663363</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-04-21T03:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404372#M663364</link>
      <description>in terms of command you can use:&lt;BR /&gt;&lt;BR /&gt;more /home/user/.sh_history file &lt;BR /&gt;&lt;BR /&gt;but no time stamp in there.</description>
      <pubDate>Tue, 21 Apr 2009 10:13:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404372#M663364</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-04-21T10:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404373#M663365</link>
      <description>and if you really need to catch everything a user does, you'll need to look at a commercial application. Something like Symark's PowerBroker can do the logging.  Don't know how much it runs, but it's probably not cheap.</description>
      <pubDate>Tue, 21 Apr 2009 15:46:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404373#M663365</guid>
      <dc:creator>OldSchool</dc:creator>
      <dc:date>2009-04-21T15:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404374#M663366</link>
      <description>Hi,&lt;BR /&gt;if you want to enabled more logs can convert your system in trusted system,&lt;BR /&gt;&lt;BR /&gt;you may get more help from hp documents for this.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.docs.hp.com/en/B2355-90121/ch01s07.html" target="_blank"&gt;http://www.docs.hp.com/en/B2355-90121/ch01s07.html&lt;/A&gt;</description>
      <pubDate>Wed, 22 Apr 2009 01:06:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404374#M663366</guid>
      <dc:creator>avizen9</dc:creator>
      <dc:date>2009-04-22T01:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404375#M663367</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Dennis, I couldn't see IP info but login/logout info are OK. How is it possible  to see IP information also?&lt;BR /&gt;&lt;BR /&gt;Hakki, the file ".sh_history" is a little useful as you said. How can I see the user actions with time stamp as I told?&lt;BR /&gt;&lt;BR /&gt;Is there any method on system?&lt;BR /&gt;Thanks a lot,&lt;BR /&gt;Ali KEMAL.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Apr 2009 23:23:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404375#M663367</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-04-28T23:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404376#M663368</link>
      <description>&amp;gt; I couldn't see IP info but login/logout info are OK. How is it possible to see IP information also?&lt;BR /&gt; &lt;BR /&gt;THe man page is very helpful. Use the commands:&lt;BR /&gt; &lt;BR /&gt;last -R -100&lt;BR /&gt;(to list the last 100 logins with IP address)&lt;BR /&gt; &lt;BR /&gt;last -R -20 billh&lt;BR /&gt;(to list the last 20 logins for billh)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; the file ".sh_history" is a little useful as you said. How can I see the user actions with time stamp as I told?&lt;BR /&gt; &lt;BR /&gt;The .sh_history is created by the shell (sh, ksh, etc) but has no option to add a timestamp. You could write a script to append a timestamp at the end of the file every few hours, but this can make the shell history recall a bit unpredictable.&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Apr 2009 00:40:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404376#M663368</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2009-04-29T00:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404377#M663369</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I could not see the new records on a server after using "last -R -100". What might happen? &lt;BR /&gt;&lt;BR /&gt;After "last -R -20 -f /var/adm/wtmp" output,&lt;BR /&gt;I see that the last record is "Apr 20".&lt;BR /&gt;I couldn' see even the last record on the file by "last -R -100". And there are no new records on the file after that date.&lt;BR /&gt;&lt;BR /&gt;What is the problem? Is it working the logging system?&lt;BR /&gt;Thanks,&lt;BR /&gt;Ali KEMAL.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Apr 2009 09:20:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404377#M663369</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-04-29T09:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404378#M663370</link>
      <description>&amp;gt;I could not see the new records on a server after using "last -R -100". What might happen?&lt;BR /&gt;&lt;BR /&gt;Since last(1) reverses the order, which direction did you mean by "new records"?&lt;BR /&gt;Did you mean there are no entries for Apr 21 and later in time?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;After "last -R -20 -f /var/adm/wtmp" output, I see that the last record is "Apr 20". I couldn't see even the last record on the file by "last -R -100". And there are no new records on the file after that date.&lt;BR /&gt;&lt;BR /&gt;You're saying last(1) indicates nobody has logged on since Apr 20?&lt;BR /&gt;How big is the file?  It could have been corrupted on april 20?</description>
      <pubDate>Wed, 29 Apr 2009 14:30:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404378#M663370</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-04-29T14:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404379#M663371</link>
      <description>&amp;gt;Since last(1) reverses the order, which direction did you mean by "new records"?&lt;BR /&gt;Did you mean there are no entries for Apr 21 and later in time?&lt;BR /&gt;&lt;BR /&gt;I use the same command on the other servers, no problem. And yes, no entries for Apr 21 and later in time?&lt;BR /&gt;&lt;BR /&gt;And, as I said, When I use "last" I could not see the entry "Apr 20" which exist in the file "wtmp".&lt;BR /&gt;&lt;BR /&gt;&amp;gt;You're saying last(1) indicates nobody has logged on since Apr 20?&lt;BR /&gt;How big is the file? It could have been corrupted on april 20? &lt;BR /&gt;&lt;BR /&gt;Yes, I am saying exactly what you said.&lt;BR /&gt;wtmp 94000 and wtmps ~2147483000&lt;BR /&gt;So, If it is corrupted, how can i solve this?&lt;BR /&gt;&lt;BR /&gt;NOTE: I can get the correct info from the command "lastb".&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ali KEMAL.&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Apr 2009 09:23:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404379#M663371</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-04-30T09:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404380#M663372</link>
      <description>Ali Kemal&lt;BR /&gt;&lt;BR /&gt;Lastb is the same as last, except that by default it shows a log of the file /var/log/btmp, which contains all the bad login attempts.  &lt;BR /&gt;</description>
      <pubDate>Sat, 02 May 2009 17:58:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404380#M663372</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-05-02T17:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404381#M663373</link>
      <description>and if your wtmp(s) file is corrupted , &lt;BR /&gt;you need to restore from last good available backup if you got.</description>
      <pubDate>Sat, 02 May 2009 18:02:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404381#M663373</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-05-02T18:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404382#M663374</link>
      <description>&amp;gt;I use the same command on the other servers, no problem.&lt;BR /&gt;&lt;BR /&gt;wtmps is a data file so it doesn't matter that happens on other systems.  How large is it on the others?  You may have to fix them too.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;wtmps ~2147483000&lt;BR /&gt;&lt;BR /&gt;Do you have largefiles enabled for /var?  You really shouldn't let it grow this big.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;If it is corrupted, how can I solve this?&lt;BR /&gt;&lt;BR /&gt;You truncate the file with:&lt;BR /&gt;&amp;gt; /var/adm/wtmps&lt;BR /&gt;&lt;BR /&gt;&amp;gt;I can get the correct info from the command "lastb".&lt;BR /&gt;&lt;BR /&gt;No, you should get no info from lastb(1) because nobody should be using bad passwords.  :-)</description>
      <pubDate>Sun, 03 May 2009 02:45:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404382#M663374</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-03T02:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404383#M663375</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;1) If I understand corectly, it is enough to truncate the corrupted file to solve the problem. And I should randomly delete some content of the file, is it right?&lt;BR /&gt;&lt;BR /&gt;2) Should I do the same deletion for wtmp and wtmps?&lt;BR /&gt;&lt;BR /&gt;3) I see the difference between "last" and "lastb". I just check the command "lastb" for bad login attempts.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ali KEMAL.&lt;BR /&gt;</description>
      <pubDate>Wed, 06 May 2009 23:23:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404383#M663375</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-05-06T23:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404384#M663376</link>
      <description>&amp;gt;1) it is enough to truncate the corrupted file to solve the problem. And I should randomly delete some content of the file, is it right?&lt;BR /&gt;&lt;BR /&gt;Yes, unless you want to keep some content.&lt;BR /&gt;No need to "randomly delete".&lt;BR /&gt;&lt;BR /&gt;&amp;gt;2) Should I do the same deletion for wtmp and wtmps?&lt;BR /&gt;&lt;BR /&gt;No, only the bad file, wtmps.&lt;BR /&gt;(What OS version are you using?)&lt;BR /&gt;</description>
      <pubDate>Thu, 07 May 2009 01:59:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404384#M663376</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-07T01:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404385#M663377</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;--Yes, unless you want to keep some content.&lt;BR /&gt;No need to "randomly delete".&lt;BR /&gt;&lt;BR /&gt;Which content should I delete or not delete?&lt;BR /&gt;Is there any risk when I do something wrong with the file?&lt;BR /&gt;&lt;BR /&gt;--No, only the bad file, wtmps.&lt;BR /&gt;(What OS version are you using?)&lt;BR /&gt;&lt;BR /&gt;HP-UX B.11.23 U.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 08 May 2009 07:53:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404385#M663377</guid>
      <dc:creator>Ali KEMAL</dc:creator>
      <dc:date>2009-05-08T07:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Event logs including info about system and users activities</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404386#M663378</link>
      <description>&amp;gt;Which content should I delete or not delete?  Is there any risk when I do something wrong with the file?&lt;BR /&gt;&lt;BR /&gt;You have to decide how much info to keep.  If you do something wrong, you just won't have that login info.</description>
      <pubDate>Sat, 09 May 2009 05:35:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/event-logs-including-info-about-system-and-users-activities/m-p/4404386#M663378</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-05-09T05:35:01Z</dc:date>
    </item>
  </channel>
</rss>

