From owner-freebsd-questions@FreeBSD.ORG Sat Jun 5 12:43:55 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 57C9D16A4CE for ; Sat, 5 Jun 2004 12:43:55 -0700 (PDT) Received: from priv-edtnes40.telusplanet.net (outbound05.telus.net [199.185.220.224]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0323143D53 for ; Sat, 5 Jun 2004 12:43:55 -0700 (PDT) (envelope-from viktorlazlo@telus.net) Received: from byx0rm.mr-clevver.com ([154.20.11.99]) by priv-edtnes40.telusplanet.netESMTP <20040605194354.JITV11934.priv-edtnes40.telusplanet.net@byx0rm.mr-clevver.com>; Sat, 5 Jun 2004 13:43:54 -0600 Date: Sat, 5 Jun 2004 12:46:26 -0700 (PDT) From: Viktor Lazlo X-X-Sender: viktorlazlo@byx0rm.mr-clevver.com To: jimmie james In-Reply-To: <20040601155631.39094.qmail@web13426.mail.yahoo.com> Message-ID: <20040605124225.F36793@byx0rm.mr-clevver.com> References: <20040601155631.39094.qmail@web13426.mail.yahoo.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: jimmiejaz@fhase.net cc: questions@freebsd.org Subject: Re: Monthly security run. X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 05 Jun 2004 19:43:55 -0000 On Tue, 1 Jun 2004, jimmie james wrote: > Doing login accounting: > total 1438.65 > jimmie 1435.18 > root 3.46 > > This all makes perfect sense, though I was wondering, > if there's an easy way to get the script to log how > many times (and optionally, who) uses "su" or "su -" > and to what account they jumped to. > > Unfortunaly, I'm not a code monkey, so digging around > in the source, and trying myself would probably break > something. You can do this easily enough by polling /var/log/messages for any use of su: grep -i su /var/log/messages | sort +6 Set this up as a daily crontab item and the results will be emailed to you automatically. Cheers, Viktor