2013-07-23 07:46 AM
You can find out if someone recently logged in if you can access the /etc/log directory of the filer in any way (CIFS share/NFS export). In the file /etc/log/auditlog, search for entries like the following:
Tue Jul 23 16:39:12 CEST [sshd_0:debug]: root:START:ssh2 shell:[192.168.1.2_42916]:password
To force a logout of a logged-in user, run the following command from an administrative host:
someuser@somehost:~$ ssh root@filer logout telnet
It will either force a logout if an interactive session is active, or report "No active telnet session is present". Don't get confused because it says "telnet": it works for both telnet and SSH sessions.