Can someone please guide how I can collect the following logs from Linux systems ?
changes to account privileges.
unsuccessful login and log off events for privileged accounts.
any access attempts using deactivated accounts
Any help on this would be highly appreciated.