5.3.12 Collect Session Initiation Information '/var/log/wtmp'
Information
Configuration Level : Level-II
Solution
Add the following lines to the /etc/audit/audit.rules file.-w /var/run/utmp -p wa -k session -w /var/log/wtmp -p wa -k session # Execute the following command to restart auditd # pkill -P 1-HUP auditdNote- Use the last command to read /var/log/wtmp (last with no parameters) and /var/run/utmp (last -f /var/run/utmp)