|
On a UNIX system there are several files that contain details of logins, logouts and other significant events. Most have some binary data that makes it difficult to see the real data. Here are a few very simple PERL programs that can be used to format and print these files. lastlogSee lastlog for information on formatting and printing /var/log/lastlog. wtmpThe wtmp log file is usually found in /var/log/wtmp and contains the following information:
The following one line PERL program will format and print /var/log/wtmp but it may need modification to work on your site.
A typical output would be:
Tue Sep 12 10:50:23 2006 Normal x23456u ftpd9915 217.154.59.173
Tue Sep 12 10:55:04 2006 Term ttyp0
Tue Sep 12 10:55:14 2006 Normal w23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 10:55:35 2006 Term ftpd9915 217.154.59.173
Tue Sep 12 11:45:00 2006 Term ttyp0
Tue Sep 12 12:15:25 2006 Normal v23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 12:45:56 2006 Term ttyp0
Tue Sep 12 12:46:18 2006 Normal h23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 15:34:36 2006 Login LOGIN tty1
Tue Sep 12 15:34:36 2006 Login LOGIN tty2
Tue Sep 12 15:34:36 2006 Login LOGIN tty3
Tue Sep 12 15:34:36 2006 Login LOGIN tty4
Tue Sep 12 15:34:36 2006 Login LOGIN tty5
Tue Sep 12 15:34:36 2006 Login LOGIN tty6
Tue Sep 12 15:34:43 2006 Normal h23456u ttyp0 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 15:45:07 2006 Normal h23456u ftpd1174 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 15:45:11 2006 Term ftpd1174 host86-129-123-5.range86-129.btcentralplus.com
Tue Sep 12 16:13:01 2006 Normal h23456u ttyp1 proton.positive-internet.com
Tue Sep 12 16:13:16 2006 Term ttyp1
Tue Sep 12 16:13:23 2006 Normal h23456u ttyp1 proton.positive-internet.com
Tue Sep 12 17:03:07 2006 Term ttyp0
|