- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- how to find out system activity
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 07:43 AM
05-10-2006 07:43 AM
how to find out system activity
actually i have faced one problem by user( who is soft Admin), particular service (soft service) has been terminated by some user( root rights) at particular time (like 11:00 AM) now i should find out who has done it, so how to find out system activity at particular time
and how to list out particular process has been run at particular time
becuase of i couldn't able to findout by syslog new & old
is any cmds to findout ?
thanks
siva
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 07:56 AM
05-10-2006 07:56 AM
Re: how to find out system activity
sulog will provide you who did su (best way to find who did at 11:00AM)
.sh_history will provide what all actiity did by at person who did su at 11:00AM.
Other way check the user's .sh_history at their home directory..!!
Chan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 08:40 AM
05-10-2006 08:40 AM
Re: how to find out system activity
/usr/sbin/acct/fwtmp < /var/adm/wtmp | more
The above command will give you the details of exactly who logged in at what time. As far as the system activity is concerned, you had be lucky if process accounting was logged in your system.
Regards,
Senthil Kumar .A
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 08:46 AM
05-10-2006 08:46 AM
Re: how to find out system activity
id you dont have sadc configured to collect data, then you wont come to know what statistics it was going thru at particular time..
just add few commands to ur cron and make it possible to see stats
also similarly you can plan some sctipt, might be itrc forums you can find some to track or log statistics on system..
Thanks
Prashant
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2006 09:24 AM
05-10-2006 09:24 AM
Re: how to find out system activity
Check the root cron schedule for jobs including the kill command.
A particular time. That is the evidence left behind by a machine.
crontab -l
carefully look at stuff running at 11 a.m.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com