Two types of logs are used to view User Logon behaviors. One is to record the user's data and the other is to record the user's logon time, record user logon data/var/log/wtmp log file record user logon data. However, this file is an encoded file and cannot be directly viewed using commands such as vi and cat. It can be read using the last command. Each logon generates a record, including the user name, logon end, and time span, as shown in the following figure: www.2cto.com [html] [root @ bogon ~] # Last root pts/1: 0.0 Wed Oct 24 still logged in root: 0 Wed Oct 24 still logged in root: 0 Wed Oct 24) reboot system boot 2.6.18-194. el5 Wed Oct 24 () root pts/1: 0.0 Mon Oct 22--09 () root: 0 Mon Oct 22-() root: 0 Mon Oct 22-() reboot system boot 2.6.18-194. el5 Mon Oct 22 () root pts/3: 0. 0 Sat Oct 13-() root pts/2: 0.0 Sat Oct 13-() root pts/1: 0.0 Sat Oct 13) root: 0 Sat Oct 13-() root: 0 Sat Oct 13-() reboot system boot 2.6.18-194. el5 Sat Oct 13 () root pts/1: 0.0 Thu Oct 11-() root: 0 Thu Oct 11-() root: 0 Thu Oct 11 20:12-20:12 (00: 00) www.2cto.com 2. Check the specific user logon/var/log/lastlog log file to record the recent logon time of each user. Each user has only one record [html] [root @ bogon ~] # Lastlog Username Port From Latest root: 0 Wed Oct 24 03:02:36-0700 2012 bin ** Never logged in ** daemon ** Never logged in ** adm ** Never logged in ** lp ** Never logged in ** sync ** Never logged in ** shutdown ** Never logged in ** halt ** Never logged in ** mail ** Never logged in ** news ** Never logged in ** uucp ** Never logged in ** operator ** Never logged in ** games ** Never logged in ** gopher ** Never logged in ** ftp ** Never logged in ** nobody ** Never logged in ** nscd ** Never logged in ** vcsa ** Never logged in ** oprofile ** Never logged in ** pcap ** Never logged in ** ntp ** Never logged in ** internal ** Never logged in ** avahi ** Never logged in ** rpc ** Never logged in ** apache ** Never logged in ** mailnull ** Never logged in ** smmsp ** Never logged in ** sshd ** Never logged in ** xfs ** Never logged in ** rpcuser ** Never logged in ** haldaemon ** Never logged in ** avahi-autoipd ** Never logged in ** gestation ** Never logged in **