I'd like to monitor logged in sessions, include how they logged in (physical console or SSH), and how long that session has existed for.
It seems like utmpdump /var/log/utmp
has that information, but I can find't the documentation that explains all the fields. Can someone enlighten me?
init
, whereas entries for users would most-probably be placed inutmp
bygetty
or variants (for console log-ins) or a login-manager likegdm
(for X11 sessions). E.g., there's also asessreg
program intended to updateutmp
for arbitrary reasons a sysadmin may find useful. – Andreas Wiese Jul 17 '15 at 09:22