Successful su for user by root in /var/log/auth.log
- by grs
I have this sorts of entries in my /var/log/auth.log:
Apr 3 12:32:23 machine_name su[1521]: Successful su for user1 by root
Apr 3 12:32:23 machine_name su[1654]: Successful su for user2 by root
Apr 3 12:32:24 machine_name su[1772]: Successful su for user3 by root
Situation:
All users are real accounts in /etc/passwd;
None of the users has…