Writer instructions

Page title

For most spaces, this page must be titled Space announcements.

For spaces with localized content, this page must be titled Space announcements l10n.

Purpose

Provide an announcement banner on every page of your space.

Location

Move this page outside of your home branch.

Guidelines

Announcement Support for this product will end on November 3, 2025. We recommend that you use PATROL for Linux, PATROL for AIX, or PATROL for Solaris to monitor operating systems.

Viewing Users that Failed to Execute su msu Commands


This task describes how to view a list of users who attempted and failed to execute a set user (su) or (msu) command.

Before you begin

To perform this task, you must provide a user account and password. It does not have to be the root account.

To View a List of Users that Failed to Execute su/msu Commands

  1. Access the SECURITY application menu as described in Accessing KM Commands and InfoBoxes.
  2. Select Administration > List Failed su/msu logins.
     BMC PATROL prompts you for a user account and password.
  3. Type the appropriate user name and password and click OK.
     BMC PATROL writes the information to a BMC PATROL task object (List Failed su/msu logins) in the UNIX OS container.
  4. Access the List Failed su/msu logins task object as described in Accessing KM Commands and InfoBoxes and view the results. Your results should resemble this example:
# PSL Serial No.: #########
<NOT INTERACTIVE>

List Failed su/msu logins
SU 01/02 15:56 - pts/8 dpallet-ssp
SU 01/17 09:39 - pts/8 rabby-root
SU 01/18 17:45 - pts/17 mmoulin-root
SU 01/23 15:13 - pts/13 nedned-root

Output Format

The output has the following format. Following table describes each field.

cmd mm/dd hh:mm - pts/# acct_from-acct_to

 List Failed su/msu logins Command Output Format 

Related topics

Security-SECURITY

Viewing-Files-with-Global-Write-Privileges

Viewing-Files-with-SUID-or-SGID-Permissions

Viewing-Users-without-Passwords

Viewing-duplicate-user-id-entry

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*