Retaining "last" log (wtmp) capability
As some people have noticed, Leopard no longer writes/retains
"wtmp" files, which means the "last" command has been crippled,
because it does not go back very far.
"last" is incredibly useful for security (to keep an eye on
suspicious logins at suspicious times from suspicious places).
Why has "last" been crippled in this way? Is there an alternative
way to retain and list that same valuable information i.e., username,
origin of the login session, time of login, and time of logout?
Yes, I have already tried:
syslog -k Facility com.apple.system.lastlog
syslog -k Facility com.apple.system.utmpx
and they do not list the information equivalent to
the "last" command. Further, the log file "asl.db"
does not seem to be retaining even the above
not-very-usefully-presented information for a long time,
as promised by "man syslogd".
Thanks for any help,
Raja.