Re: OpenBSM: does somebody work on it?
- From: Patrick Proniewski <patpro@xxxxxxxxxx>
- Date: Wed, 29 Jun 2011 14:26:44 +0200
On 29 juin 2011, at 12:59, Lev Serebryakov wrote:
auditreduce doesn't filter events by date (-b/-a/-d options with any
arguments produces empty output), it doesn't merge files properly and
doesn't pick up files automagically, as Solaris' one does. It doesn't
have -C/-M/-O functionality of Solaris' one, too. So, proper merging
of audit trial files seems to be impossible :(
I could try to fix & extend auditreduce(1), but does somebdy but me
need it?
Does somebody use audit on FreeBSD on production systems?
I do, almost (I've not finished my settup, but I'm auditing a production server).
May be you'll find this interesting: http://forums.freebsd.org/showthread.php?t=23716#9
patpro
- Follow-Ups:
- Re: OpenBSM: does somebody work on it?
- From: Lev Serebryakov
- Re: OpenBSM: does somebody work on it?
- References:
- OpenBSM: does somebody work on it?
- From: Lev Serebryakov
- OpenBSM: does somebody work on it?
- Prev by Date: OpenBSM: does somebody work on it?
- Next by Date: Re: OpenBSM: does somebody work on it?
- Previous by thread: OpenBSM: does somebody work on it?
- Next by thread: Re: OpenBSM: does somebody work on it?
- Index(es):
Relevant Pages
|