[Klug-general] Auditing SSH login sessions

Colin McCarthy binarysignal at gmail.com
Fri May 27 12:05:28 UTC 2011


On 27 May 2011 12:47, Paul Littlefield <info at paully.co.uk> wrote:

> On 27/05/11 12:40, James Morris wrote:
>
>> Last reads /var/log/wtmp by default, rather than /var/log/auth.log
>>
>
> Hhhmm, here's some output from one of my servers...
>
> $ last -a plittlefield
>
> plittlef pts/0        Fri May 27 12:43   still logged in    192.168.0.73
> plittlef ssh          Fri May 27 12:43   still logged in    192.168.0.73
>

Thans everyone for responses. Alan's 'last' command seems to do the trick,
as I have similar output.
Although the user account in question does not have ssh next to any of the
entries, but pts/1, pts/2, pts/8 etc.

What does the pts/* stand for?

Colin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.lug.org.uk/pipermail/kent/attachments/20110527/2950392a/attachment.htm>


More information about the Kent mailing list