Linux Process Accounting: Difference between revisions

From Leo's Notes
This page was last edited on 1 May 2020, at 23:58.
Created page with "Process accounting on Linux captures all process activities by all users on a system. It allows a system administrator to audit what was executed, the amount of CPU time and m..."
 
mNo edit summary
Line 30: Line 30:
# systemctl start psacct
# systemctl start psacct
}}
}}
== See Also ==
* https://www.cyberciti.biz/tips/howto-log-user-activity-using-process-accounting.html
* https://www.cyberciti.biz/faq/linux-unix-bsd-varaccountpacct-or-varlogaccountpacct-file/

Revision as of 23:58, 1 May 2020

Process accounting on Linux captures all process activities by all users on a system. It allows a system administrator to audit what was executed, the amount of CPU time and memory the process used, and the date and time of when the process was executed.

Process accounting command cheat sheet:

Command Description
accton Turns on process accounting
ac Displays statistics about how a user has logged on
lastcomm Displays the last commands that was executed
sa Summarizes information on previous executed commands

Installation

Red Hat based systems get the process accounting binaries from the psacct package.

# dnf install psacct

The psacct.service systemd service needs to then be enabled and started.

# systemctl enable psacct
# systemctl start psacct

See Also