<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send audit logging to syslog for centralized syslog server in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265732#M472676</link>
    <description>I hope, this thread will be helpful to read.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1454565" target="_blank"&gt;http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1454565&lt;/A&gt;</description>
    <pubDate>Wed, 08 Dec 2010 03:05:54 GMT</pubDate>
    <dc:creator>Shibin_2</dc:creator>
    <dc:date>2010-12-08T03:05:54Z</dc:date>
    <item>
      <title>Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265731#M472675</link>
      <description>Running HP-UX 11.23.  I'm wanting to send the auditing information to the syslog so it will go to our centralized syslog server.  Because this additional logging has the potential to create big log files, I don't need or want them to be on the local system.  I have been successful in getting the syslogs to go to the centralized syslog server by adding the following line in the syslog.conf file:&lt;BR /&gt;*.info @&lt;IPADDRESS&gt;&lt;BR /&gt;I have tried using #audsys | logger and that doesn't seem to be working.  Can anyone offer me some insight?&lt;/IPADDRESS&gt;</description>
      <pubDate>Tue, 07 Dec 2010 20:10:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265731#M472675</guid>
      <dc:creator>Paul Maglinger</dc:creator>
      <dc:date>2010-12-07T20:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265732#M472676</link>
      <description>I hope, this thread will be helpful to read.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1454565" target="_blank"&gt;http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1454565&lt;/A&gt;</description>
      <pubDate>Wed, 08 Dec 2010 03:05:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265732#M472676</guid>
      <dc:creator>Shibin_2</dc:creator>
      <dc:date>2010-12-08T03:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265733#M472677</link>
      <description>I don't believe this will work.  This is on a system running NIS for authentication and therefore isn't trusted. The workaround I used was to installed enhanced security, which then allowed me to run auditing.  I just can't get the auditing to go to the syslog.  I tried installing syslog-ng, but I can't run the GUI on 11.23.  The reference manual was too vague for me to be able to use.  I do not wish to tail because I'd like it to be logged in real time.  Putting it in cron would cause it to be batched, would it not?  Any other thoughts from anyone?</description>
      <pubDate>Wed, 08 Dec 2010 17:51:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265733#M472677</guid>
      <dc:creator>Paul Maglinger</dc:creator>
      <dc:date>2010-12-08T17:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265734#M472678</link>
      <description>I have gone to another system that is not using NIS and implemented auditing.  I have told it to audit create, delete, chmod, etc.&lt;BR /&gt;&lt;BR /&gt;After which I did created a file using touch, chmod, chgrp, vi'ed the file, and then deleted it.   Shouldn't I have been able to see these changes in the auditlog?  And shouldn't it show the file that was created/changed/removed?</description>
      <pubDate>Wed, 08 Dec 2010 22:48:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265734#M472678</guid>
      <dc:creator>Paul Maglinger</dc:creator>
      <dc:date>2010-12-08T22:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265735#M472679</link>
      <description>I'm going back to square one.  Can anyone tell me how to direct the auditing results either in addition to or just directly to the syslog?</description>
      <pubDate>Thu, 16 Dec 2010 22:53:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265735#M472679</guid>
      <dc:creator>Paul Maglinger</dc:creator>
      <dc:date>2010-12-16T22:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265736#M472680</link>
      <description>Assuming that auditing uses the auth facility, you can direct just the auth entries to your syslog server like this:&lt;BR /&gt; &lt;BR /&gt;auth.info @&lt;IPADDRESS&gt;&lt;BR /&gt; &lt;BR /&gt;To keep the auth records from showing up in syslog.log, add: auth.none to the syslog.log entry like this:&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;*.info;mail.none;auth.none /var/adm/syslog/syslog.log&lt;BR /&gt;auth.info @&lt;IPADDRESS&gt;&lt;BR /&gt; &lt;BR /&gt;NOTE: NO SPACES! Every space in the syslog.conf file causes the entire to be silently ignored. Use TAB to separate elements.&lt;BR /&gt; &lt;BR /&gt;However, it appears (man audsys) that audsys never uses syslog because the log can grow VERY fast (dozens of MB in minutes). Conversely, the default location for audsys logs is /, the dumbest place for log files. So you can script an audsys logfile scanner (tail will never work because the logfiles are switched regularly). The scanner would find the newest file, then use logger to extract the last record as well as determine (with wc) the file size. Then every few seconds, check the file size and grab all new records and send them using logger. The script will also have to monitor the audsys logfile switch. Not elegant, but that's the way audsys works.&lt;BR /&gt; &lt;BR /&gt;NOTE: audsys can generate massively large logs and therefore massive network traffic when configured inappropriately.&lt;/IPADDRESS&gt;&lt;/IPADDRESS&gt;</description>
      <pubDate>Fri, 17 Dec 2010 00:03:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265736#M472680</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2010-12-17T00:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Send audit logging to syslog for centralized syslog server</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265737#M472681</link>
      <description>HP-UX auditing sure seems to be lacking in many respects.  The output from audisp is cryptic at best.  I can't see where it specifically shows that a file has been modified, a feature that would seem to be key to any auditing.  If anyone knows of a better solution, I like to hear about it.</description>
      <pubDate>Tue, 01 Feb 2011 15:50:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/send-audit-logging-to-syslog-for-centralized-syslog-server/m-p/5265737#M472681</guid>
      <dc:creator>Paul Maglinger</dc:creator>
      <dc:date>2011-02-01T15:50:14Z</dc:date>
    </item>
  </channel>
</rss>

