{"id":2156,"date":"2023-06-28T07:00:00","date_gmt":"2023-06-28T07:00:00","guid":{"rendered":"https:\/\/myvlcsys.com\/?p=2156"},"modified":"2023-06-07T19:33:40","modified_gmt":"2023-06-07T19:33:40","slug":"linux-historial-de-accesos-al-sistema","status":"publish","type":"post","link":"https:\/\/myvlcsys.com\/?p=2156","title":{"rendered":"LINUX: Historial de accesos al sistema."},"content":{"rendered":"\n<p>Es muy frecuente que la gesti\u00f3n de un servidor GNU\/Linux, se realice por varios usuarios. Y es muy posible que en alg\u00fan momento necesites saber el historial de inicio de sesi\u00f3n por algunos de estos, e incluso averiguar la ip con la que conectaron contra el sistema. <\/p>\n\n\n\n<p>En este articulo vamos a ver, como revisar el historial de acceso de sesi\u00f3n en nuestro sistema.<\/p>\n\n\n\n<p>La informaci\u00f3n de inicio de sistema se registra en los los siguientes ficheros:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\/var\/log\/wtmp: registros de los \u00faltima sesi\u00f3n de inicio de sesi\u00f3n.<\/li><li>\/var\/run\/utmp: registros de las sesiones de inicio de sesi\u00f3n actuales.<\/li><li>\/var\/log\/btmp: registro de los intentos de inicio de sesi\u00f3n incorrectos.<\/li><\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:24px\"><strong>Ver el historial de todos los usuarios registrados:<\/strong><\/p>\n\n\n\n<p>Con el comando <strong><em><mark style=\"background-color:#000000\" class=\"has-inline-color has-white-color\">last<\/mark><\/em><\/strong> podemos observar, se enumera el usuario, la direcci\u00f3n IP, la fecha, la hora del inicio de sesi\u00f3n y el tiempo que dur\u00f3 la sesi\u00f3n.&nbsp;<code>pts\/1<\/code>&nbsp;o&nbsp;<code>pts\/0<\/code>&nbsp;significa que se accedi\u00f3 a trav\u00e9s de SSH.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"886\" height=\"621\" data-id=\"2159\" src=\"https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando-last.png\" alt=\"\" class=\"wp-image-2159\" srcset=\"https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando-last.png 886w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando-last-300x210.png 300w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando-last-768x538.png 768w\" sizes=\"(max-width: 886px) 100vw, 886px\" \/><figcaption>comando last<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<p>La \u00faltima l\u00ednea de la salida se indica cu\u00e1ndo se cre\u00f3 el archivo de registro&nbsp;<code>wtmp<\/code>. Esto es un detalle importante, porque si el archivo&nbsp;<code>wtmp<\/code>&nbsp;se elimina, el comando&nbsp;<code>last<\/code>&nbsp;no podr\u00e1 mostrar el historial de los inicios de sesi\u00f3n anteriores a esa fecha.<\/p>\n\n\n\n<p style=\"font-size:24px\"><strong>Ver el historial de un usuario determinado:<\/strong><\/p>\n\n\n\n<p>Si tan s\u00f3lo quisi\u00e9ramos filtar por un usuario podemos hacerlo con el comando <mark style=\"background-color:#000000\" class=\"has-inline-color has-white-color\">last nombre_de_usario<\/mark>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"874\" height=\"322\" src=\"https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lsat_2.png\" alt=\"\" class=\"wp-image-2160\" srcset=\"https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lsat_2.png 874w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lsat_2-300x111.png 300w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lsat_2-768x283.png 768w\" sizes=\"(max-width: 874px) 100vw, 874px\" \/><figcaption>Comando last + usuario<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Para verificar los intentos fallidos de inicio de sesi\u00f3n a nuestro sistema. Lo haremos con el comando <strong><mark style=\"background-color:#000000\" class=\"has-inline-color has-white-color\">lastb<\/mark><\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"929\" height=\"557\" src=\"http:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lastb.png\" alt=\"\" class=\"wp-image-2162\" srcset=\"https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lastb.png 929w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lastb-300x180.png 300w, https:\/\/myvlcsys.com\/wp-content\/uploads\/2023\/06\/comando_lastb-768x460.png 768w\" sizes=\"(max-width: 929px) 100vw, 929px\" \/><figcaption>Comando lastb<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Es muy frecuente que la gesti\u00f3n de un servidor GNU\/Linux, se realice por varios usuarios. Y es muy posible que en alg\u00fan momento necesites saber el historial de inicio de&hellip; <\/p>\n","protected":false},"author":4,"featured_media":2066,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[10],"tags":[31,26,25,47,27,24],"class_list":["post-2156","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","tag-comandos","tag-debian","tag-linux","tag-myvlcsys","tag-sistemas","tag-terminal"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/posts\/2156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2156"}],"version-history":[{"count":5,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/posts\/2156\/revisions"}],"predecessor-version":[{"id":2166,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/posts\/2156\/revisions\/2166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=\/wp\/v2\/media\/2066"}],"wp:attachment":[{"href":"https:\/\/myvlcsys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/myvlcsys.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}