Linux process audit record user action record

Source: Internet
Author: User

1, install Psacct
m–y Install Psacct
2 starting the service
/etc/init.d/psacct Start
3, activation process audit
touch/var/log/pact
accton/var/log/pact

[[email protected] ~]# AC
Total 324.67
[email protected] ~]# ac-p
Root 324.25
Birdman 0.42
Total 324.67
[email protected] ~]# ac-d
APR Total 8.55
APR Total 26.07
APR Total 1.19
APR Total 18.60
APR Total 57.70
APR Total 15.91
APR Total 32.06
APR -Total 15.62
APR Total 22.36
APR Total 27.38
May 2 Total 19.26
May 3 Total 20.55
May 6 Total 30.41
May 7 Total 13.95
May 8 Total 14.32
Today Total 0.74

find the commands the user has performed in the past
You can use the Lastcomm command to print out commands that the user has executed in the past. You can also search for previously executed commands by user name, TTY name, or command name.
Lastcomm Birdman
lastcomm hostname
Lastcomm pts/0



Statistics Accounting Information
You can use the SA command to print statistics about past execution commands. In addition, the SA command holds a file called Savacct, which contains the number of times the command was invoked and the number of times the resource was used. And SA also provides statistics for each user, This information is stored in a file called Usracct.


shows the number of processes per user and the number of CPU times
[email protected] ~]# Sa-u|tail
root 0.00 CPU 1196k MEM Bash *
root 0.00 CPU 1196k MEM Bash *
root 0.00 CPU 1086k mem awk
root 0.00 CPU 1196k MEM Bash *
root 0.00 CPU 1065k MEM ID
root 0.00 CPU 1196k MEM Bash *
root 0.00 CPU 962k Mem who
root 0.00 CPU 1196k MEM Bash *
root 0.00 CPU 996k Mem Date
root 0.00 CPU 1196k MEM Bash *


[email protected] ~]# sa-m
786 36.66re 0.04CP 1278k
Root 772 36.65re 0.04CP 1078k
postgres 0.01re 0.00cp 13110k
sshd 1 0.00re 0.00cp 2144k
find out who's consuming CPU
you can find out the suspicious activity by looking at Re, K, cp/cpu (see output explained above), or a user/command takes up all of the CPU time. If the Cpu/memeory use Number (command) is increasing, you can indicate that there is a problem with the command.

This article is from the "I am a Little bird" blog, please make sure to keep this source http://2242558.blog.51cto.com/2232558/1545330

Linux process audit record user action record

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.