Originally posted by: SystemAdmin
John: the definitive way to investigate something like this is via AIX auditing. The bad news is that audit doesn't run by default, you have to customize and set it up to your requirements. The best reference for this is the redbook
http://www.redbooks.ibm.com/abstracts/sg246396.html?Open If you didn't have auditing running you're probably in bad shape I hate to say. You could try looking back through syslog (if you have that set up properly). You probably became aware of this situation through some symptoms or other. These may be reflected in syslog and that might at least give you a timeframe as to when the problem started. Given that you could use the last command to see who was logged on at the time. You could also try looking for and at smit.log files in case the culprit was using smit.
HTH
Jim Lane
#AIX-Forum