Solaris 10 BSM Auditing help



Hello,

I am new to Solaris 10 and I am seeking some assistance with the
following auditing configuration in Solaris 10.

1. I would like to know if it is possible to edit the audit classes
(lo,fm,ad, etc) on the fly via command line rather than having to edit
the the audit_control file manually. The reason for this is that I am
using RBAC and the security role has permissions to "audit review" and
"audit control" but not to edit the audit_control file or
stop/start/restart services. If there is another way around this, I am
certainly open to alternative solutions.

2. I am unable to get any changes I make to the audit classes in the
audit_control file registered into the auditing sub-system. If I edit
the audit_control file as root then issue an audit -s and do an
"auditconfig -getaudit" I do not see that the changes have taken
effect. (eg - flags:lo,ua,fm and nflags:lo,ua,fm). I have tried an
"auditconfig -conf" and "auditconfig -aconf" as well to no avail. I
have even stopped and started the audit daemon (svcadm disable/enable
system/auditd) with no luck. The only way I can get a change (addition
or removal of audit classes) to the audit_control file to take effect
is to reboot the system and this, of course is not ideal at all.

Any advice is very much appreciated.

Thank you,
B. Wheaton

Originally a Solaris Admin
Briefly an HP-UX admin
Glad to be back into Solaris!

.



Relevant Pages

  • Solaris 10 BSM Auditing help
    ... I am new to Solaris 10 and I am seeking some assistance with the ... following auditing configuration in Solaris 10. ... I would like to know if it is possible to edit the audit classes ...
    (comp.unix.solaris)
  • Solaris 10 BSM Auditing help
    ... I am new to Solaris 10 and I am seeking some assistance with the ... following auditing configuration in Solaris 10. ... I would like to know if it is possible to edit the audit classes ...
    (comp.sys.sun.admin)
  • Re: IDS Error - VP Notify
    ... I've just had the same problem, but with a solaris ... Solaris patch information for the IBM Informix Dynamic Server ... Location of Shared Memory ... Configuring the Operating System Audit Subsystem: ...
    (comp.databases.informix)
  • Re: System freeze while saving /etc/hosts file in vi
    ... I'm experiencing a strange problem on a SuSE 10.2 system. ... prevous edit". ... ## This file contains the a sample audit configuration intended to ... 1Successful and unsuccessful logons and logoffs. ...
    (alt.os.linux.suse)
  • Re: Allen B - Code to Audit changes
    ... Temporarily comment out the error handler at the beginning of each of the ... The fact that you get the audit record once only suggests that you have left ... I NEVER got the "Edit TO" record. ... the AutoNum Key in the Audit table is ...
    (microsoft.public.access.forms)