Where is the terminal "last" command getting it's information from?

I searching for the information that the terminal "last" command holds.
When I execute the "last' command...... I am seeing too little to be real..... something is up..... I need to determine when the information was deleted.
What log file is the last command using? In Mt. Lion, in Lion, in Snow Leopard?
Thanx for your help

For those who are reading this, this is about a Mt. Lion system with current patches 10.8.3
Thank you for the reply and the pointer to the audit directory.
I am continuing to ponder why last at the terminal is given unexpected behavior. I am now noticing the history in last is only for the "last" - no pun intended - 24 hours or there abouts on one of my systems. In the audit directory there are many more entries
Wed Mar 20 09:47:14 terry@mymac:~ >>last
terry   ttys001                   Wed Mar 20 09:47   still logged in
terry   ttys000                   Wed Mar 20 09:47   still logged in
terry   console                   Wed Mar 20 09:41   still logged in
reboot    ~                         Wed Mar 20 09:39
shutdown  ~                         Wed Mar 20 09:39
terry   ttys001                   Wed Mar 20 09:03 - 09:13  (00:09)
terry   ttys000                   Wed Mar 20 09:03 - 09:13  (00:09)
terry   console                   Wed Mar 20 09:03 - 09:39  (00:35)
reboot    ~                         Wed Mar 20 09:00
wtmp begins Wed Mar 20 00:56
>>sudo ls -lsa /var/audit/
256 -r--r-----
1 root  wheel   130862 Nov 24 14:52 20121124213110.20121124225215
  56 -r--r-----
1 root  wheel
26733 Nov 24 15:23 20121124225256.20121124232301
  40 -r--r-----
1 root  wheel
19634 Nov 24 15:43 20121124232348.20121124234351
and then DOZENS and DOZENS more.... and finally those for yesterday are missing and then today.
2016 -r--r-----
1 root  wheel  1031355 Mar 18 23:31 20130318150701.20130319063139
840 -r--r-----
1 root  wheel   426232 Mar 20 00:56 20130319154442.20130320075621
  56 -r--r-----
1 root  wheel
26259 Mar 20 09:39 20130320160056.20130320163908
  40 -r--r-----
1 root  wheel
19050 Mar 20 09:55 20130320163956.not_terminated
Also when I look thru the list of audit file  the 15th and the 10th of Mar are missing..... hummmmm...
Any idea what could cause this?
I am suspicion of some sort of hacking but just see any direct evidence of it ....
I have gone an gotten the source code for last at the BSD project but Im' not a c programmer and apple's version is a branch or so it seems to me cause they've got to be different and I'm not sure where to configure last or how to better understand what I'm seeing.
Anyone care to help me understand what could be going on?

Similar Messages

  • Sending Mail to Local Users via the Terminal mail Command

    I am having trouble sending mail to other user account via the terminal mail command. It seems to work with some accounts i.e. guest, etc, but fails with others i.e. Dennis. It will fail with no error message. Has anyone had any experience using the unix mail command locally ?
    Dennis

    I don't know the answer to this but you might try the -v option on the mail command in order to get verbose output. Perhaps a useful message would pop up.
    Also, you might consider posting this message in the Unix Forum. There is a good chance that someone there can help you with this issue.
    EMAC G4 1.0 GHz   Mac OS X (10.4.6)  

  • Where is the batch process command in Bridge CS6?

    Where is the batch process command in Bridge CS6?  I want to convert to Tiffs.

    Found it. Woohoo!

  • Where is the best place to get/read information of the pros and cons on updating my OS from Snow Leopard to the current OS?

    Where is the best place to get/read information on the pros and cons of updating my OS from Snow Leopard to the current OS?
    I have an iMac 27" intel, purchased Nov 2009.  I am currently using 10.6.8

    Apple OS 10.9 Mavericks:
    Quick overview:
    https://help.apple.com/osx-mavericks/whats-new-from-mountain-lion
    OS X Mavericks supports the following Macs that are already running a minimum of Snow Leopard:
    iMac (Mid-2007 or later)
    MacBook (13-inch Aluminum, Late 2008), (13-inch, Early 2009 or later)
    MacBook Pro (13-inch, Mid-2009 or later), (15-inch, Mid/Late 2007 or later), (17-inch, Late 2007 or later)
    MacBook Air (Late 2008 or later)
    Mac Mini (Early 2009 or later)
    Mac Pro (Early 2008 or later)
    Xserve (Early 2009)
    Transitioning your Mac from Mountain Lion to Apple's new OS X 10.9 Mavericks
    http://appleinsider.com/articles/13/10/23/transitioning-your-mac-from-mountain-l ion-to-apples-new-os-x-109-mavericks

  • Where does the Value of EECST gets stored

    Hi,
    Where does the value of EECST gets stored for the infotype p0167. How can it be retrieved from that specific infotype. - Urgent issue.
    Thanks........
    sk

    hi,
    what is EECST?
    there is no such field in data dictionary.
    plz specify properly or atleast u give the name of field in general that is used in pa0167 infotype so that we can help u.

  • Where is the extend edit command in Premiere CC ? I want to assign a shortcut for it. Thank you

    Where is the extend edit command in Premiere CC ? I want to assign a shortcut for it. Thank you

    Do you mean these?

  • Where's the best place to get code converted between ActionScript 2.0 and 3.0?

    Where's the best place to get code converted between ActionScript 2.0 and 3.0?
    If I just have occasional (very small) projects, what's the best way to get them done really fast by somebody who knows both 2.0 and 3.0?
    Thanks, Dan

    You have pretty much answered your own question... hire someone who has fairly thorough knowledge of both AS2 and AS3.
    I have heard there are some tools for converting between AS2 and AS3, but I have no knowledge of them other than having heard that they cannot convert all things.... which makes sense because there is not always a one-to-one relationship to how things ae done with AS2 and how they get done with AS3.

  • Where is the Terminal Window Groups settings saved?

    Where is the Terminal Window Groups settings saved?  Would love to copy my Window Groups and customization to another computer.

    It's stored in the standard Terminal preferences file, namely ~/Library/Preferences/com.apple.Terminal.plist

  • Where do the MEDIA FILES live after I import them from camera to iMovie (Mac Mini OS X 10.9.2)?  I need to MOVE MEDIA FILES to external hard drive.

    Where do the MEDIA FILES live after I import them from camera to iMovie (Mac Mini OS X 10.9.2)?  I need to MOVE MEDIA FILES to external hard drive.

    Hello bbryson68,
    Thanks for using Apple Support Communities.
    From your post I understand you're wanting to move iMovie project and event data to another drive.  I found the following information in the iMovie help that answers your question.
    Copy or move projects, events, or clips between libraries or storage devices
    Connect a storage device that contains the target library to your Mac, or copy the target library to your Mac.
    Choose File > Open Library, and choose an option from the submenu.You can choose from recently opened libraries, locate an existing library on your Mac, or create a new library.The selected library is opened in the Libraries list, with the first event selected and its contents displayed in the browser.
    In the Libraries list, select the event that contains the item you want to move or copy.
    In the browser, select the item you want to move or copy.Tip:  To select multiple clips or projects in the same library, hold down the Command key as you click the items you want to select, or drag a selection rectangle around the items.
    Do one of the following:
    To move items between events or libraries: Drag the clip or project to another event or library.
    To copy items between events or libraries: Option-drag the clip or project to another event or library by first starting to drag and then holding down the Option key as you drag.
    Work with multiple libraries
    http://help.apple.com/imovie/mac/10.0/#mov3fa25bae7
    Take care,
    Alex H.

  • What is the simplest  way to get a xml-file from 10g R2 -database ?

    Hi,
    I'm new in xml, there are so many tools to work with xml:
    what is the simplest way to get a xml-file from 10g R2 -database ?
    I have : 10g R2 and a xsd.file to describe the xml-structure
    thank you
    Norbert

    There is no automatic way to generate XML documents from an arbitary set of relational tables using the information contained in an XML Schema. Typically the easiest way to generate XML from relational data is to use the SQL/XML operators (XMLElement, XMLAGG, XMLAttribtues, XMLForest). There are many examples of using these operators in the forums You can validate the generated XML against the XML Schema by registering the XML Schema with XML DB and then using the XMLType.SchemaValidate() method

  • Where is the App icon for HD 1080p Video? From the online photos it should be separate from the camera App.

    Where is the App icon for HD 1080p Video? From the online photos it should be separate from the camera App.
    It's supposed to have a blue background with 1080p in white, while inside there is a white camera with the letters HD in blue.
    I cannot find this App icon. Where is it located? It was supposed to be preinstalled.
    Thanks.

    There is no app.
    It is the camera.  Just take video with the camera.
    iPhone User Guide (For iOS 5.1 Software)

  • Will the iPod nano 7 get a new update from the current 1.0.3?

    Hey Guys I was wondering will the iPod nano 7 get a new update from the current 1.0.3?
    If anyone knows or has and info or rumors pleas tell me.
    Thanks
    email *****
    <edited by host>

    Apple might release small updates for 4th generation iPods touch if they find serious issues like the FaceTime problem that made Apple release iOS 6.1.5 for the 4th generation iPod touch. However, this device won't receive any major iOS update.
    The 4th generation iPod touch has got 256 MB of memory, and iOS 7 devices have got 512 MB or more of memory

  • Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine

    Hello,
    When implementing a VDI solution, I'm getting an error on our virtualization host server.  The error is:
    Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine [VDI-PC].
    Hresult 0x8000FFFF
    Event ID 8467, Severity: Warning, Source: Microsoft-Windows-TerminalServices\TSV\VmHostAgent
    This error happens every time a user or admin connects to a VDI desktop.  This is a fresh install of Remote Desktop Services on completely fresh servers.  This is in testing and we have not ever had it working before without the error.
    Topolgy: Server2012 R2, Windows 7
    Srv-RDCB1: Is the connection broker and Web Access server.  It is Virtualized thru Hyper=V.
    Srv-RDVH1: Is the virtualization host.  It is a physical server. It also has a separated hyper-v role (for RDS VDI deployment).
    Everything seems to be functional other than this error in the log, and I haven't found any information on what this could mean.
    Any help is greatly appreciated, thanks!

    Hello. I have this trouble too.
    All roles on one server.
    Deployment type - Quick start
    Deployment Scenario Virtual mashine-based desktop deplyment
    Reinstall all roles 2 times
    Warning TerminalServices-TSV-VmHostAgent
    8467 Orchestration
    Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine [per-0] . 
    Hresult: 0x8000FFFF
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-TerminalServices-TSV-VmHostAgent" Guid="{92618A87-2F6A-4B75-9AE2-E77BE7EAF43C}"
    />
      <EventID>8467</EventID>
      <Version>0</Version>
      <Level>3</Level>
      <Task>22</Task>
      <Opcode>14</Opcode>
      <Keywords>0x4000000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-11T13:24:45.579138000Z" />
      <EventRecordID>1655</EventRecordID>
      <Correlation
    ActivityID="{F4200EF7-FEDD-4CAD-9F5D-6219A5F30000}" />
      <Execution ProcessID="3164" ThreadID="13164" />
      <Channel>Microsoft-Windows-TerminalServices-TSV-VmHostAgent/Operational</Channel>
      <Computer>blade2.vzfei.local</Computer>
      <Security UserID="S-1-5-20" />
      </System>
    <UserData>
    <EventXML xmlns="Event_NS">
      <param1>per-0</param1>
      <param2>0x8000ffff</param2>
      </EventXML>
      </UserData>
     </Event>
    In RD Gateway Manager, right-click on the RD RAP and click Properties.  On Network Resources tab select
    “Allow users to connect to any network resource”.
    not work.

  • Where is the apps icon so I can transfer stuff from my computer to my iphone?

    I am trying to download items from my computer to my Iphone but in the help it says to connect my iphone then click apps where is the apps? on the computer or on the iphone and where on the computer?

    Hi there!
    "download items from my computer to my Iphone": are you using iTunes? if so, refer to these guides:
    Sync your iPhone, iPad and iPod with iTunes using USB - Apple Support
    Thank you for using Apple Support Communities.
    All the very best,
    James

  • How can I get CDP neighbor information from access point reports in Cisco Prime 2.0

    How can I get CDP neighbor information from access point reports in Cisco Prime 2.0?  I have looked through all the reports and I cannot find a report that gives me the CDP neighbor information of an access point.  I thought that information was in there, however I cannot seem to find it.
    Thanks in advance!

    Hi
    You can get this from an inventory report in PI (Select Report Type AP). Here is an example of PI 2.1 works for me. Once you export this into excel you can sort based on controllers & filter the single controller connected AP you want.
    Regards
    Rasika
    **** Pls rate all useful responses ****

Maybe you are looking for