Article 5PBFC wtmp flooded with security scan user

wtmp flooded with security scan user

by
PoleStar
from LinuxQuestions.org on (#5PBFC)
Hello,

I am trying to understand behavior of last/wtmp.
We run security scan every night on the servers. On all the servers when I try to do "last" all I see is pages and pages of security scan user.. no information about any real user loging in.
While /var/log/wtmp.1 is usually empty.

How can I restrict security scan user to flood the /var/log/wtmp... or how can I retain clean information about the other users loging in ?

Thank youlatest?d=yIl2AUoC8zA latest?i=cJi0X0McDK4:Otk2DH1NbRI:F7zBnMy latest?i=cJi0X0McDK4:Otk2DH1NbRI:V_sGLiP latest?d=qj6IDK7rITs latest?i=cJi0X0McDK4:Otk2DH1NbRI:gIN9vFwcJi0X0McDK4
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments