Execute the lastb command separately. It reads the file named btmp located in the/var/log directory and stores the file content
All user names that have failed to log on are displayed.
Syntax
Lastb [-adRx] [-f <Record File>] [-n <display number of columns>] [account name...] [terminal number...]
Parameter description:
- -A displays the host name or IP address from which to log on to the system in the last row.
- -D. Convert the IP address to the host name.
- -F <Record File> specifies the record file.
- -N <display columns> or-<display columns> sets the number of columns displayed in the list.
- -R does not display the host name or IP address used to log on to the system.
- -X displays information such as system shutdown, reboot, and change of execution level.
Instance
Show logon failed users
# Lastb
Root tty7: 1 Thu May 13)
Btmp begins Thu May 13 11:26:39 2014