<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog.conf file configuration in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469242#M360940</link>
    <description>As mentioned, not everything here can go into syslog facility. There are some 3rd party products that work real well and should satisfy your requirements.&lt;BR /&gt;&lt;BR /&gt;All actions by individual with administrative rights - can use the 'rootsh' in conjunction with sudo. This creates a log file that logs every key stroke. Use this with sudo and you can see when sudo was invoked. The sudo log can be appended to the syslog.&lt;BR /&gt;&lt;BR /&gt;Invalid login - this is logged in the syslog file on a trusted system, can also use the 'last' &amp;amp; 'lastb' commands which come from the wtmp  &amp;amp; btmp files&lt;BR /&gt;&lt;BR /&gt;Creation/Deletion of system level objects - unsure exactly what you mean but if you are talking OS level files (or any file for that matter) look into tripwire; it is on the iExpress.&lt;BR /&gt;&lt;BR /&gt;Initialize audit log - the OS will log these events, in the rc.log at boot and typically in the syslog already.&lt;BR /&gt;&lt;BR /&gt;Authentication events - you can get from the 'last' command to see who logon when and for how long.&lt;BR /&gt;&lt;BR /&gt;Unfortunately, not everything will be in 1 location unless you jump through some hoops and customize.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 30 Jul 2009 16:36:52 GMT</pubDate>
    <dc:creator>Rick Garland</dc:creator>
    <dc:date>2009-07-30T16:36:52Z</dc:date>
    <item>
      <title>Syslog.conf file configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469239#M360937</link>
      <description>Hi there,&lt;BR /&gt;&lt;BR /&gt;We gonna have to integrate HP-UX server to a centralized RSA enVision Log management tool for meeting our compliance requirements.&lt;BR /&gt;&lt;BR /&gt;From HP-UX we need to enable the following events by editing the /etc/syslog.conf file:&lt;BR /&gt;&lt;BR /&gt;* All actions taken by any individual with administrative privileges&lt;BR /&gt;&lt;BR /&gt;* Initialization of the audit logs&lt;BR /&gt;&lt;BR /&gt;* Creation and deletion of system-level objects&lt;BR /&gt;&lt;BR /&gt;* Authentication events (Log off/Logon)&lt;BR /&gt;&lt;BR /&gt;* Invalid Logon attempts due to incorrect password.&lt;BR /&gt;&lt;BR /&gt;It would be great if you could let me know the &lt;BR /&gt;facility.level combination for the events above. For e.g I'm aware for authentication events I'd use "auth.debug". For other I'm not quite sure about the facility which handles such events. Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;V</description>
      <pubDate>Wed, 29 Jul 2009 14:35:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469239#M360937</guid>
      <dc:creator>Venkatesh_16</dc:creator>
      <dc:date>2009-07-29T14:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf file configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469240#M360938</link>
      <description>Folks, any takers for this post? I've got points to offer. Thx&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Jul 2009 13:20:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469240#M360938</guid>
      <dc:creator>Venkatesh_16</dc:creator>
      <dc:date>2009-07-30T13:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf file configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469241#M360939</link>
      <description>The majority of these cannot be done with syslog.&lt;BR /&gt;&lt;BR /&gt;You would probably be better off looking at other products and see if that fit a part of what you need.&lt;BR /&gt;&lt;BR /&gt;Things that come to mind -- &lt;BR /&gt;&lt;BR /&gt;Role Based Access Control (RBAC) from HP.  &lt;BR /&gt;&lt;A href="http://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl" target="_blank"&gt;http://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;PowerBroker from Symark&lt;BR /&gt;&lt;A href="http://www.symark.com/products/pboverview.html" target="_blank"&gt;http://www.symark.com/products/pboverview.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;Creation and deletion of system-level objects&lt;BR /&gt;&lt;BR /&gt;I'm not sure what you mean by this.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Jul 2009 15:13:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469241#M360939</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2009-07-30T15:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog.conf file configuration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469242#M360940</link>
      <description>As mentioned, not everything here can go into syslog facility. There are some 3rd party products that work real well and should satisfy your requirements.&lt;BR /&gt;&lt;BR /&gt;All actions by individual with administrative rights - can use the 'rootsh' in conjunction with sudo. This creates a log file that logs every key stroke. Use this with sudo and you can see when sudo was invoked. The sudo log can be appended to the syslog.&lt;BR /&gt;&lt;BR /&gt;Invalid login - this is logged in the syslog file on a trusted system, can also use the 'last' &amp;amp; 'lastb' commands which come from the wtmp  &amp;amp; btmp files&lt;BR /&gt;&lt;BR /&gt;Creation/Deletion of system level objects - unsure exactly what you mean but if you are talking OS level files (or any file for that matter) look into tripwire; it is on the iExpress.&lt;BR /&gt;&lt;BR /&gt;Initialize audit log - the OS will log these events, in the rc.log at boot and typically in the syslog already.&lt;BR /&gt;&lt;BR /&gt;Authentication events - you can get from the 'last' command to see who logon when and for how long.&lt;BR /&gt;&lt;BR /&gt;Unfortunately, not everything will be in 1 location unless you jump through some hoops and customize.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Jul 2009 16:36:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-conf-file-configuration/m-p/4469242#M360940</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2009-07-30T16:36:52Z</dc:date>
    </item>
  </channel>
</rss>

