On a UNIX system there are several files that contain details of logins, logouts and other significant events. Most have some binary data that makes it difficult to see the real data. Here are a few very simple PERL programs that can be used to format and print these files. lastlogSee lastlog for information on formatting and printing /var/log/lastlog. wtmpThe wtmp log file is usually found in /var/log/wtmp and contains the following information:
The following one line PERL program will format and print /var/log/wtmp but it may need modification to work on your site.
A typical output would be: Tue Sep 12 10:50:23 2006 Normal x23456u ftpd9915 217.154.59.173 Tue Sep 12 10:55:04 2006 Term ttyp0 Tue Sep 12 10:55:14 2006 Normal w23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 10:55:35 2006 Term ftpd9915 217.154.59.173 Tue Sep 12 11:45:00 2006 Term ttyp0 Tue Sep 12 12:15:25 2006 Normal v23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 12:45:56 2006 Term ttyp0 Tue Sep 12 12:46:18 2006 Normal h23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 15:34:36 2006 Login LOGIN tty1 Tue Sep 12 15:34:36 2006 Login LOGIN tty2 Tue Sep 12 15:34:36 2006 Login LOGIN tty3 Tue Sep 12 15:34:36 2006 Login LOGIN tty4 Tue Sep 12 15:34:36 2006 Login LOGIN tty5 Tue Sep 12 15:34:36 2006 Login LOGIN tty6 Tue Sep 12 15:34:43 2006 Normal h23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 15:45:07 2006 Normal h23456u ftpd1174 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 15:45:11 2006 Term ftpd1174 host86-129-123-5.range86-129.btcentralplus.com Tue Sep 12 16:13:01 2006 Normal h23456u ttyp1 proton.positive-internet.com Tue Sep 12 16:13:16 2006 Term ttyp1 Tue Sep 12 16:13:23 2006 Normal h23456u ttyp1 proton.positive-internet.com Tue Sep 12 17:03:07 2006 Term ttyp0 |