5.11. Monitoring login/logout events

To compile with support for this option, use the configure option

./configure --enable-login-watch

samhain can be compiled to monitor login/logout events of system users. For initialization, the system utmp file is searched for users currently logged in. To recognize changes (i.e. logouts or logins), the system wtmp file is then used. This facility is configured in the Utmp section of the configuration file:

  [Utmp]  
  #  
  # activate (0 for switching off) 
  # 
  LoginCheckActive=1 
  #  
  # interval between checks (in seconds)
  # 
  LoginCheckInterval=600 
  #  
  # these are the severities (see section Section 4.1.1) 
  # 
  SeverityLogin=info 
  SeverityLogout=info 
  #  
  # multiple logins by same user 
  # 
  SeverityLoginMulti=crit