<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to enable Audit log  for specific users and events in HP-UX 11.31 ? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078426#M729778</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;As per management decission, I need to enable audit trail in HP-UX .&amp;nbsp; So I have enable audit by command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;audsys -n&lt;/STRONG&gt; . So now how to configure it only for users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please need assist&amp;nbsp; for this issue from expert end.&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2020 05:14:14 GMT</pubDate>
    <dc:creator>Ashraf1</dc:creator>
    <dc:date>2020-02-09T05:14:14Z</dc:date>
    <item>
      <title>How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078426#M729778</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;As per management decission, I need to enable audit trail in HP-UX .&amp;nbsp; So I have enable audit by command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;audsys -n&lt;/STRONG&gt; . So now how to configure it only for users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please need assist&amp;nbsp; for this issue from expert end.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 05:14:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078426#M729778</guid>
      <dc:creator>Ashraf1</dc:creator>
      <dc:date>2020-02-09T05:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078493#M729779</link>
      <description>&lt;P&gt;Take a look at this technical paper on the subject:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c02899022" target="_blank" rel="noopener"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c02899022&lt;/A&gt;&lt;/P&gt;&lt;P&gt;p15 onwards starts to describe how to configure auditing for specific users and events, but I would read the whole thing to get a better understanding of what's really going on.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:51:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078493#M729779</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2021-05-18T12:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078501#M729780</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Enabling auditing on HP-UX requires fair knowlegde on how it works. Since it deals with Security, you must take time to read through the documentation.&lt;/P&gt;&lt;P&gt;One more important aspect is managing the auditing logs. For example, unless you plan properly you run the risk of exhausting file system space. And there is a need to archive them on a regualr basis for record-keeping etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest that you go through the documentations for auditing thouroughly before embarking on this journey. You will find all documents at this location -&amp;nbsp;&lt;A href="http://www.hpe.com/info/hpux-security-docs" target="_blank"&gt;http://www.hpe.com/info/hpux-security-docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Some of the documents I usually refer are:&lt;/P&gt;&lt;P&gt;HP-UX 11iv2 and 11iv3 Security Configuring and Managing the Auditing System&lt;/P&gt;&lt;P&gt;HP-UX System Administrators Guide Security Management HP-UX 11i Version 3&lt;/P&gt;&lt;P&gt;Hope it helps. All the best.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 09:37:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078501#M729780</guid>
      <dc:creator>KishJ</dc:creator>
      <dc:date>2020-02-10T09:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078503#M729781</link>
      <description>&lt;P&gt;Hello again,&lt;/P&gt;&lt;P&gt;The events, users, calls etc that can be configured are documented in&amp;nbsp;/etc/audit/audit.conf. Site-specific config files will have to be included in another file&amp;nbsp;/etc/audit/audit_site.conf.&lt;/P&gt;&lt;P&gt;The events can also be passed againts&amp;nbsp;AUDEVENT_ARGS in&amp;nbsp;/etc/rc.config.d/auditing&lt;/P&gt;&lt;P&gt;As I mentioned in my earlier post, it is important that you read through the documentation to understand how the auditing on HP-UX works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 09:47:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078503#M729781</guid>
      <dc:creator>KishJ</dc:creator>
      <dc:date>2020-02-10T09:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078514#M729782</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to all for sharing the comments including document&amp;nbsp; site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Already I have studied some documents . However I will check and go through all provided documents.&lt;/P&gt;&lt;P&gt;Tomorrow , I will share my new queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ashraf&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 10:24:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078514#M729782</guid>
      <dc:creator>Ashraf1</dc:creator>
      <dc:date>2020-02-10T10:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078566#M729783</link>
      <description>&lt;P&gt;As&amp;nbsp; you can see from the depth of the auditing system, there can be an immense effort to setup and maintain the records. Then there is the question on how to immediately notify sysadmins of a potential problem.&lt;/P&gt;&lt;P&gt;You may find that simply keeping the login shell history would satisfy your management's request. Note that this would cover simple commands and possible mistakes, but would not be adequate for knowledgeable users trying to hide their activities.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 17:23:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078566#M729783</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2020-02-10T17:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable Audit log  for specific users and events in HP-UX 11.31 ?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078633#M729784</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have studied all document as per my strenth.&lt;/P&gt;&lt;P&gt;I have run all command in my test system. Here OS version is HP-UX 11.31&amp;nbsp;&amp;nbsp; . After success, then we will run on live system&lt;/P&gt;&lt;P&gt;I have set to audit for user &lt;STRONG&gt;root&lt;/STRONG&gt; and &lt;STRONG&gt;oracle&lt;/STRONG&gt; only. Please check the command output as bellow .(#&lt;STRONG&gt;userdbget -a | grep AUDIT_FLAG=1)&lt;/STRONG&gt;&lt;BR /&gt;I set only the events associated with the basic profile for auditing, use the following&amp;nbsp;&amp;nbsp; command:&lt;BR /&gt;# &lt;STRONG&gt;audevent -P -F -r basic&lt;/STRONG&gt; , please check the config log as bellow&amp;nbsp; by # cat /etc/audit/audit.conf&lt;/P&gt;&lt;P&gt;Also check the output by # &lt;STRONG&gt;cat /etc/rc.config.d/auditing&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;From /var/.audit location, I see the bellow file size&lt;/P&gt;&lt;P&gt;bash-4.3# du -sk a&lt;STRONG&gt;udfile2.20200211_1235&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;12312&lt;/STRONG&gt; audfile2.20200211_1235&lt;BR /&gt;bash-4.3# du -sk &lt;STRONG&gt;audfile2.20200211_1241&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;1776&lt;/STRONG&gt; audfile2.20200211_1241&lt;/P&gt;&lt;P&gt;Command output:&lt;/P&gt;&lt;P&gt;bash-4.3# userdbget -a | grep AUDIT_FLAG=1&lt;BR /&gt;root AUDIT_FLAG=1&lt;BR /&gt;oracle AUDIT_FLAG=1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;bash-4.3# cat /etc/rc.config.d/auditing&lt;/P&gt;&lt;P&gt;AUDITING=1&lt;BR /&gt;PRI_AUDFILE=/var/.audit/audfile1&lt;BR /&gt;PRI_SWITCH=1000&lt;BR /&gt;SEC_AUDFILE=/var/.audit/audfile2&lt;BR /&gt;SEC_SWITCH=1000&lt;BR /&gt;AUDEVENT_ARGS1=" -P -F -e create -e delete -e moddac -e modaccess -e open -e close -e process -e removable -e login -e admin -e ipccreat -e ipcopen -e ipcclose -e uevent1 -e uevent2 -e uevent3 -e ipcdgram -e readdac -s exit -s fork -s open -s close -s creat -s link -s unlink -s execv -s chdir -s mknod -s chmod -s chown -s .chmod_link -s mount -s umount -s setuid -s stime -s ptrace -s access -s kill -s stat -s setpgrp3 -s lstat -s pipe -s setgid -s acct -s reboot -s symlink -s .set_sys_info -s execve -s umask -s chroot -s fcntl -s ulimit -s vfork -s mmap -s munmap -s setgroups -s setpgid -s swapon -s fstat -s setpriority -s settimeofday -s fchown -s fchmod -s setresuid -s setresgid -s rename -s truncate -s ftruncate -s mkdir -s rmdir -s setrlimit -s .priv_grp_ctl -s rtprio -s plock -s lockf -s semget -s semop -s msgget -s shmget -s shmat -s shmdt -s .setmemwindow -s setdomainname -s vfsmount -s setacl -s fsetacl -s setaudid -s setaudproc -s setevent -s audswitch -s audctl -s getaccess -s fchdir -s accept -s bind -s connect -s recv -s recvfrom -s recvmsg -s send -s sendmsg -s sendto -s setsockopt -s shutdown -s socket -s socketpair -s semctl -s msgctl -s shmctl -s mpctl -s adjtime -s fattach -s fdetach -s serialize -s lchown -s sched_setparam -s sched_setscheduler -s clock_settime -s .perf_tool_ctl -s ftruncate64 -s fstat64 -s lockf64 -s lstat64 -s mmap64 -s setrlimit64 -s stat64 -s truncate64 -s setpgrp -s setregid -s mlock -s munlock -s mlockall -s munlockall -s shm_open -s shm_unlink -s sigqueue -s mq_open -s mq_close -s mq_unlink -s sem_open -s sem_unlink -s sem_close -s ttrace -s sendfile -s .sendfile_by_name -s sendfile64 -s modload -s moduload -s modpath -s getksym -s .kernel_module_ctl -s modstat -s .processor_ctl -s acl -s .p2p_bcopy_ctl -s .gang_sched_ctl -s .mrgctl -s settune -s pset_create -s pset_destroy -s pset_assign -s pset_bind -s pset_setattr -s pset_ctl -s __pset_rtctl -s .perf_ctl -s semtimedop -s .audit_tag_ctl -s .proc_sec_ctl -s .file_sec_ctl -s .cmpt_rules -s .postwait_ctl -s umount2 -s .setaudevent -s .procsm_setop -s .cachefsstat -s swapctl -s .audit_ctl -s .proc_mgmt_ctl -s .cell_olstar_lock -s .cell_olstar_specify -s .cell_olstar_backout -s .cell_olstar_unlock -s .cell_olstar_operate"&lt;BR /&gt;AUDEVENT_ARGS2=""&lt;BR /&gt;AUDEVENT_ARGS3=""&lt;BR /&gt;AUDEVENT_ARGS4=""&lt;BR /&gt;AUDOMON_ARGS=" -p 20 -t 1 -w 90"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;bash-4.3# cat /etc/audit/audit.conf&lt;BR /&gt;#&lt;BR /&gt;# Default audit event mapping information&lt;BR /&gt;#&lt;BR /&gt;# DO NOT MODIFY THIS FILE. All site specific customerizations&lt;BR /&gt;# need to go into /etc/audit/audit_site.conf.&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;EVENT create= creat, mknod, pipe, symlink, mkdir, semget, msgget, shmget,&lt;BR /&gt;shmat, pset_create, SELFAUD_EVENT create&lt;/P&gt;&lt;P&gt;EVENT delete= rmdir, semctl, msgctl, shm_unlink, mq_unlink, sem_unlink,&lt;BR /&gt;pset_destroy, SELFAUD_EVENT delete&lt;/P&gt;&lt;P&gt;EVENT moddac= chmod, chown, umask, fchown, fchmod, semop, setacl, fsetacl,&lt;BR /&gt;lchown, acl, semtimedop, .chmod_link, SELFAUD_EVENT moddac&lt;/P&gt;&lt;P&gt;EVENT modaccess= link, unlink, chdir, setuid, setpgrp, setpgrp3, setgid,&lt;BR /&gt;chroot, ulimit, setgroups, setpgid, setresuid, setresgid, rename,&lt;BR /&gt;fcntl, lockf, shmdt, fchdir, shmctl, lockf64, setregid, .proc_sec_ctl,&lt;BR /&gt;.file_sec_ctl, .cmpt_rules, SELFAUD_EVENT modaccess&lt;/P&gt;&lt;P&gt;EVENT open= open, execv, execve, mmap, truncate, ftruncate, ftruncate64,&lt;BR /&gt;mmap64, truncate64, shm_open, mq_open, sem_open, ttrace, ptrace,&lt;BR /&gt;sendfile, sendfile64, .sendfile_by_name, SELFAUD_EVENT open&lt;/P&gt;&lt;P&gt;EVENT close= close, munmap, mq_close, sem_close, SELFAUD_EVENT close&lt;/P&gt;&lt;P&gt;EVENT process= exit, fork, kill, vfork, setpriority, rtprio, mlock,&lt;BR /&gt;munlock, mlockall, munlockall, sigqueue, SELFAUD_EVENT process&lt;/P&gt;&lt;P&gt;EVENT removable= mount, umount, umount2, vfsmount, SELFAUD_EVENT removable&lt;/P&gt;&lt;P&gt;EVENT login= SELFAUD_EVENT login&lt;/P&gt;&lt;P&gt;EVENT admin= stime, acct, reboot, swapon, setevent, settimeofday, setrlimit,&lt;BR /&gt;plock, swapctl, setdomainname, setaudid, setaudproc, audswitch,&lt;BR /&gt;audctl, .audit_ctl, .setaudevent, mpctl, adjtime, serialize,&lt;BR /&gt;sched_setparam, sched_setscheduler, clock_settime, setrlimit64,&lt;BR /&gt;modload, moduload, modpath, getksym, modstat, settune, pset_assign,&lt;BR /&gt;pset_bind, pset_setattr, pset_ctl, __pset_rtctl, .procsm_setop,&lt;BR /&gt;.priv_grp_ctl, .setmemwindow, .mrgctl, .audit_tag_ctl, .perf_ctl,&lt;BR /&gt;.perf_tool_ctl, .processor_ctl, .p2p_bcopy_ctl, .gang_sched_ctl,&lt;BR /&gt;.cell_olstar_backout, .cell_olstar_lock, .cell_olstar_operate,&lt;BR /&gt;.cell_olstar_specify, .cell_olstar_unlock, .kernel_module_ctl,&lt;BR /&gt;.set_sys_info, .proc_mgmt_ctl, .postwait_ctl, .cachefsstat,&lt;BR /&gt;SELFAUD_EVENT admin&lt;/P&gt;&lt;P&gt;EVENT ipccreat= bind, socket, socketpair, SELFAUD_EVENT ipccreat&lt;/P&gt;&lt;P&gt;EVENT ipcopen= accept, connect, fattach, SELFAUD_EVENT ipcopen&lt;/P&gt;&lt;P&gt;EVENT ipcclose= shutdown, fdetach, SELFAUD_EVENT ipcclose&lt;/P&gt;&lt;P&gt;EVENT uevent1= SELFAUD_EVENT uevent1&lt;/P&gt;&lt;P&gt;EVENT uevent2= SELFAUD_EVENT uevent2&lt;/P&gt;&lt;P&gt;EVENT uevent3= SELFAUD_EVENT uevent3&lt;/P&gt;&lt;P&gt;EVENT ipcdgram= SELFAUD_EVENT ipcdgram&lt;/P&gt;&lt;P&gt;EVENT readdac= access, stat, lstat, fstat, getaccess, fstat64, lstat64,&lt;BR /&gt;stat64, SELFAUD_EVENT readdac&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS gethostname= .set_sys_info&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS sethostname= .set_sys_info&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS uname= .set_sys_info&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS ustat= .set_sys_info&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS setuname= .set_sys_info&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS setsid= setpgrp3&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS setpgrp= setpgrp3&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS setpgrp2= setpgid&lt;/P&gt;&lt;P&gt;SYSCALL_ALIAS setprivgrp= .priv_grp_ctl&lt;/P&gt;&lt;P&gt;EVENT_ALIAS logoff= EVENT login&lt;/P&gt;&lt;P&gt;EVENT_ALIAS exec= execv, execve&lt;/P&gt;&lt;P&gt;EVENT_ALIAS net= EVENT ipccreat, EVENT ipcopen, EVENT ipcclose, EVENT ipcdgram&lt;/P&gt;&lt;P&gt;EVENT_ALIAS pset= pset_create, pset_destroy, pset_assign,&lt;BR /&gt;pset_bind, pset_setattr&lt;/P&gt;&lt;P&gt;EVENT_ALIAS sock= bind, recv, recvfrom, recvmsg, send, sendmsg, sendto,&lt;BR /&gt;setsockopt, socket, socketpair&lt;/P&gt;&lt;P&gt;PROFILE basic= EVENT admin, EVENT login, SELFAUD_EVENT moddac, execv, execve,&lt;BR /&gt;EVENT_ALIAS pset&lt;/P&gt;&lt;P&gt;bash-4.3# pwd&lt;BR /&gt;/var/.audit&lt;BR /&gt;bash-4.3# ls -la&lt;BR /&gt;total 288&lt;BR /&gt;drwxr-xr-x 220 root sys 131072 Feb 11 12:35 .&lt;BR /&gt;dr-xr-xr-x 28 bin bin 8192 Jan 2 17:44 ..&lt;BR /&gt;drwx------ 2 root sys 96 Dec 29 09:53 audfile1&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:00 audfile2.20200209_1100&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:07 audfile2.20200209_1107&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:21 audfile2.20200209_1121&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:30 audfile2.20200209_1130&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:34 audfile2.20200209_1134&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:39 audfile2.20200209_1139&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 11:51 audfile2.20200209_1151&lt;BR /&gt;drwx------ 2 root root 96 Feb 9 12:05 audfile2.20200209_1205&lt;/P&gt;&lt;P&gt;drwx------ 2 root root 96 Feb 11 11:21 audfile2.20200211_1121&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 11:36 audfile2.20200211_1136&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 11:50 audfile2.20200211_1150&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 12:05 audfile2.20200211_1205&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 12:20 audfile2.20200211_1220&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 12:35 audfile2.20200211_1235&lt;BR /&gt;drwx------ 2 root root 96 Feb 11 12:41 audfile2.20200211_1241&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;My query is as bellow&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;1.how to set time interval for file generate (suppoose , each file generate every 15 minutes)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;2.how to create report from some specific file or all file ?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;3.I have reboot the OS by root user but I don't find record from file for reboot which is mention in admin EVENT.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Please assit on this above issue .&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;Waiting&amp;nbsp; response from expert end.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 07:14:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-to-enable-audit-log-for-specific-users-and-events-in-hp-ux/m-p/7078633#M729784</guid>
      <dc:creator>Ashraf1</dc:creator>
      <dc:date>2020-02-11T07:14:28Z</dc:date>
    </item>
  </channel>
</rss>

