APLawrence.com -  Resources for Unix and Linux Systems, Bloggers and the self-employed

I need information from "last", but most of it is gone! (Old Sco Unix)

(SCO) The default root crontab cleans out /usr/adm/sulog, /etc/wtmp and /etc/wtmpx on Sunday mornings. The script that does this is /etc/cleanup.

(Linux) Logrotate does the cleaning, so modify /etc/logrotate.conf.

(BSD) uses "newsyslog".

But if system accounting is on, "runacct" does this.

If your machine is used at the time this script is run, you will want to change the time in crontab. If you want more than 1 week's information in these files, you need to change its frequency or take it out all together.

# grep wtmp /etc/cleanup
# If accounting isn't enabled, clean up wtmp and wtmpx,
: Do nothing - accounting will clean up wtmp and wtmpx
[ -f /etc/wtmp ] && >/etc/wtmp
[ -f /etc/wtmpx ] && >/etc/wtmpx

.

Having that run on Sunday is not ideal for forensics - "who logged in over the w weekend?" is not an unusual question.

A good modification might be to output "last" to a file before cleaing it.

~

Got something to add? Send me email.





(OLDER)    <- More Stuff -> (NEWER)    (NEWEST)   

Printer Friendly Version

-> -> (SCO Unix) I need information from 'last', but most of it is gone!

1 comment



Increase ad revenue 50-250% with Ezoic





Sat May 17 05:35:48 2008: 4201   anonymous


Or - rotate utmp/wtmp/wtmpx log files. No logrotate comes with OSR5 so you might want to write a small shell script to suit your purposes. Then use last with -W to specify filename to view a historical wtmp.

------------------------
Kerio Samepage


Have you tried Searching this site?

Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more.

Contact us





If you don't know anything about computers, just remember that they are machines that do exactly what you tell them but often surprise you in the result. (Richard Dawkins)





This post tagged: