<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic audit log in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510229#M218124</link>
    <description>Hi ,&lt;BR /&gt;our system is hp-ux 11.23&lt;BR /&gt;we already convert the system to trust system , and apply audit log for some users &amp;amp; events , but we have a concern about the audit log file ,, if the user delete any file it is gave onle event is rmdir but doesn't gave us the file name which is deleted ,,, how we can get this information &lt;BR /&gt;the following is an example for delete file&lt;BR /&gt;050322 17:33:34 20130 S         137       19348     15          0          3          0          3 pts/tb&lt;BR /&gt;[ Event=rmdir; User=manal; Real Grp=sys; Eff.Grp=sys;  ]&lt;BR /&gt;&lt;BR /&gt;     RETURN_VALUE 1 = 0;&lt;BR /&gt;     PARAM #1 (file path) = 0 (cnode);&lt;BR /&gt;                            0x40000008 (dev);&lt;BR /&gt;                            10032 (inode);&lt;BR /&gt;              (path) = /var/sam/core</description>
    <pubDate>Wed, 23 Mar 2005 05:45:25 GMT</pubDate>
    <dc:creator>EAB</dc:creator>
    <dc:date>2005-03-23T05:45:25Z</dc:date>
    <item>
      <title>audit log</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510229#M218124</link>
      <description>Hi ,&lt;BR /&gt;our system is hp-ux 11.23&lt;BR /&gt;we already convert the system to trust system , and apply audit log for some users &amp;amp; events , but we have a concern about the audit log file ,, if the user delete any file it is gave onle event is rmdir but doesn't gave us the file name which is deleted ,,, how we can get this information &lt;BR /&gt;the following is an example for delete file&lt;BR /&gt;050322 17:33:34 20130 S         137       19348     15          0          3          0          3 pts/tb&lt;BR /&gt;[ Event=rmdir; User=manal; Real Grp=sys; Eff.Grp=sys;  ]&lt;BR /&gt;&lt;BR /&gt;     RETURN_VALUE 1 = 0;&lt;BR /&gt;     PARAM #1 (file path) = 0 (cnode);&lt;BR /&gt;                            0x40000008 (dev);&lt;BR /&gt;                            10032 (inode);&lt;BR /&gt;              (path) = /var/sam/core</description>
      <pubDate>Wed, 23 Mar 2005 05:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510229#M218124</guid>
      <dc:creator>EAB</dc:creator>
      <dc:date>2005-03-23T05:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510230#M218125</link>
      <description>EAB,&lt;BR /&gt;according to:&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B2355-90121/ch02s05.html#tab2-1" target="_blank"&gt;http://docs.hp.com/en/B2355-90121/ch02s05.html#tab2-1&lt;/A&gt;&lt;BR /&gt;rm is not a seperately auditable event.&lt;BR /&gt;So I assume if you can not add it from the list of audited system calls, you are stuck with the details you currently get.&lt;BR /&gt;Regards</description>
      <pubDate>Wed, 23 Mar 2005 06:39:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510230#M218125</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-03-23T06:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510231#M218126</link>
      <description>so how can i know the file which is deleted by the user... &lt;BR /&gt;the audit log doen't contain any information about the deleted file or the file which is changed ....!!!&lt;BR /&gt;is there any way to get this information</description>
      <pubDate>Wed, 23 Mar 2005 06:49:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510231#M218126</guid>
      <dc:creator>EAB</dc:creator>
      <dc:date>2005-03-23T06:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: audit log</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510232#M218127</link>
      <description>EAB,&lt;BR /&gt;just to confirm by earlier response:&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=643941" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=643941&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This is perhaps not the cleanest way, but if you wrap a script around the rm command to write the name of the file to be deleted to a file, together with the user calling the rm command, you would get your audit log.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;</description>
      <pubDate>Thu, 31 Mar 2005 02:16:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-log/m-p/3510232#M218127</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-03-31T02:16:10Z</dc:date>
    </item>
  </channel>
</rss>

