Re: Audit Explanations

From: Darren J Moffat (darrenm@eng.sun.com)
Date: 08/14/01


Date: Tue, 14 Aug 2001 10:07:35 -0700 (PDT)
From: Darren J Moffat <darrenm@eng.sun.com>
To: Jeff Leckemby <Jeff.Leckemby@sptrm.com>
Subject: Re: Audit Explanations
Message-ID: <Pine.GSO.4.21.0108141005410.162164-100000@jurassic>

On Tue, 14 Aug 2001, Jeff Leckemby wrote:

> explains, tells, deciphers what the text in a typical audit record means.
> Granted some are obvious, f.e. chmod and login entries... but others aren't
> so easily defined. I am familiar with Audit Token Structure, praudit and
> auditreduce, docs.sun.com. etc., but these sources/tools haven't been too
> helpful. If any of you know of where I can look for explanations of audit
> events I would be truly grateful for your help. I have attached a snippet
> of an audit file below for reference.

You need to be a lot more specific in what you want to know.

What parts of the audit records you listed do you not understand ?
What is it you are trying to achieve ?

--
Darren J Moffat



Relevant Pages

  • [PATCH] Light-weight Auditing Framework
    ... as the ability to audit system calls, ... void do_syscall_trace ... int fastcall path_lookup ... +/* The audit_buffer is used when formatting an audit record. ...
    (Linux-Kernel)
  • Re: Is it a facade
    ... >> The classes inside the Audit Module under consideration is building ... >> this Audit record. ... > Normally an original audit record is pretty simple and is easily ... > activity is different, probably with different clients). ...
    (comp.object)
  • Re: question about column types and lengths
    ... each table and create and audit record for each insert update delete. ... know all the different collength values. ... when generating an insert the sid doesn't need quotes ...
    (comp.databases.informix)
  • RE: CBO Selection utilizing the same table
    ... Use the IDAudit and the New "AuditVersion" as a composite primary key. ... the IDAudit and Audit Version. ... To use the combo to look up an audit record, ... a date range and a client among other fields. ...
    (microsoft.public.access.forms)
  • RE: Audit Explanations
    ... Subject: Audit Explanations ... Jeff Leckemby wrote: ... > subject,someuser,someuser,staff,someuser,staff,313,312,0 0 someputer ...
    (Focus-SUN)