<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: audfile log files continually switching in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606334#M733486</link>
    <description>Hi again,&lt;BR /&gt;&lt;BR /&gt;audsys&lt;BR /&gt;auditing system is currently on&lt;BR /&gt;current file: /var/log/secure/audfile2&lt;BR /&gt;next    file: /var/log/secure/audfile1&lt;BR /&gt;statistics:  afs Kb  used Kb    avail % fs Kb  used Kb   avail %&lt;BR /&gt;current file: 1000000      121 100 8388608   29872     100&lt;BR /&gt;next    file:       0   -1068546688       0        0          0   2004692016&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Next file values are nor realistic here. From your output i can say that your system only switch to next file "/var/log/secure/audfile1" when the log file excceds 1GB value. But as i said before if it switches to next file "/var/log/secure/audfile1" then it will not switch to "/var/log/secure/audfile2" if you not set it as the next file and it is empty.&lt;BR /&gt;&lt;BR /&gt;So what do you see in syslog.log? Switch entries between files?&lt;BR /&gt;The current audit file is switched from /var/log/secure/audfile1 to /var/log/secure/audfile2&lt;BR /&gt;The current audit file is switched from /var/log/secure/audfile2 to /var/log/secure/audfile1</description>
    <pubDate>Thu, 25 Mar 2010 10:22:14 GMT</pubDate>
    <dc:creator>Turgay Cavdar</dc:creator>
    <dc:date>2010-03-25T10:22:14Z</dc:date>
    <item>
      <title>audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606328#M733480</link>
      <description>Hi...&lt;BR /&gt;&lt;BR /&gt;The system is trusted and has two auditfiles. They auditing system is configured to switch at 500mb. The auditing filesystem is 8Gb in size as has almost 100% free. audomon is set to 20 and 90 so no problems there, however the auditfile keeps switching after only a small file size.. I am puzzled.. Any idea?</description>
      <pubDate>Wed, 24 Mar 2010 11:56:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606328#M733480</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-24T11:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606329#M733481</link>
      <description>Hi,&lt;BR /&gt;normally auditing system does not keep switching, it only switches to "next" audit trail and start growing there unless you gibe them another next file. If it is switching then i think someone manually switches the logs or there is crontab script switch the logs.</description>
      <pubDate>Wed, 24 Mar 2010 13:19:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606329#M733481</guid>
      <dc:creator>Turgay Cavdar</dc:creator>
      <dc:date>2010-03-24T13:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606330#M733482</link>
      <description>Hi,&lt;BR /&gt;normally auditing system does not keep switching, it only switches to "next" audit trail and start growing there unless you gibe them another next file. If it is switching then i think someone manually switches the logs or there is crontab script switch the logs.&lt;BR /&gt;&lt;BR /&gt;Hi, there is no crontab entry and no one is manually switching. It switches roughly every 4 minutes or so.. If I execute audsys on its own, it shows the correct switch sizes, but never gets to them before it switches. audting is not being restarted as can be seen in the syslog.</description>
      <pubDate>Wed, 24 Mar 2010 13:52:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606330#M733482</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-24T13:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606331#M733483</link>
      <description>Hi again,&lt;BR /&gt;Can you post the OS version and &lt;BR /&gt;# audsys</description>
      <pubDate>Wed, 24 Mar 2010 17:00:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606331#M733483</guid>
      <dc:creator>Turgay Cavdar</dc:creator>
      <dc:date>2010-03-24T17:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606332#M733484</link>
      <description>Hi audsys output attached.. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 25 Mar 2010 08:06:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606332#M733484</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T08:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606333#M733485</link>
      <description>Also OS version 11.23. Its an IA 64 server.</description>
      <pubDate>Thu, 25 Mar 2010 08:36:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606333#M733485</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T08:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606334#M733486</link>
      <description>Hi again,&lt;BR /&gt;&lt;BR /&gt;audsys&lt;BR /&gt;auditing system is currently on&lt;BR /&gt;current file: /var/log/secure/audfile2&lt;BR /&gt;next    file: /var/log/secure/audfile1&lt;BR /&gt;statistics:  afs Kb  used Kb    avail % fs Kb  used Kb   avail %&lt;BR /&gt;current file: 1000000      121 100 8388608   29872     100&lt;BR /&gt;next    file:       0   -1068546688       0        0          0   2004692016&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Next file values are nor realistic here. From your output i can say that your system only switch to next file "/var/log/secure/audfile1" when the log file excceds 1GB value. But as i said before if it switches to next file "/var/log/secure/audfile1" then it will not switch to "/var/log/secure/audfile2" if you not set it as the next file and it is empty.&lt;BR /&gt;&lt;BR /&gt;So what do you see in syslog.log? Switch entries between files?&lt;BR /&gt;The current audit file is switched from /var/log/secure/audfile1 to /var/log/secure/audfile2&lt;BR /&gt;The current audit file is switched from /var/log/secure/audfile2 to /var/log/secure/audfile1</description>
      <pubDate>Thu, 25 Mar 2010 10:22:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606334#M733486</guid>
      <dc:creator>Turgay Cavdar</dc:creator>
      <dc:date>2010-03-25T10:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606335#M733487</link>
      <description>Yes in the syslog it switches from audfile1 to audfile2 and back to audfile1 every 5 or so minutes. The files don't even reach a 100mb in size. Yes the audsys output does look strange, but I can find no reason why it looks like this.</description>
      <pubDate>Thu, 25 Mar 2010 10:26:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606335#M733487</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T10:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606336#M733488</link>
      <description>Auditing is configured to use both files I can provide the configuration output to show how auditing is started that includes the primary and secondary file and their file switch sizes..</description>
      <pubDate>Thu, 25 Mar 2010 10:29:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606336#M733488</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T10:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606337#M733489</link>
      <description>If you can stop the auditing on the system, you can fist backup the audit files then you can try:&lt;BR /&gt;&lt;BR /&gt;# audsys -f&lt;BR /&gt;# cp /dev/null /var/log/secure/audfile1 &lt;BR /&gt;# cp /dev/null /var/log/secure/audfile2&lt;BR /&gt;# audsys -n -c /var/log/secure/audfile1 -s 1000000 -x /var/log/secure/audfile2 -z 1000000&lt;BR /&gt;&lt;BR /&gt;Then see what happens...&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 25 Mar 2010 10:33:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606337#M733489</guid>
      <dc:creator>Turgay Cavdar</dc:creator>
      <dc:date>2010-03-25T10:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606338#M733490</link>
      <description>Hi, for the purposes of the test I can do this, the command line shown above, is exactly the same as is currently executed though so should show no change in behaviour.</description>
      <pubDate>Thu, 25 Mar 2010 14:35:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606338#M733490</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T14:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606339#M733491</link>
      <description>Ran the above suggestion, at 16:24 started auditing using the above command line. At 16:27 auditing switched to the second file and switched back again 4 minutes later and has continued doing so..</description>
      <pubDate>Thu, 25 Mar 2010 15:48:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606339#M733491</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-25T15:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: audfile log files continually switching</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606340#M733492</link>
      <description>I have discovered the problem.. We are using Realsecure on all our servers and when it starts it manages to hook into the audit subsystem and sets the audit switch size as 5000kb. Even if you stop and start auditing it makes no difference. &lt;BR /&gt;&lt;BR /&gt;When you start Realsecure it states that it is setting the max audit file size to 5000kb. Problem solved..</description>
      <pubDate>Fri, 26 Mar 2010 15:02:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audfile-log-files-continually-switching/m-p/4606340#M733492</guid>
      <dc:creator>N Ward</dc:creator>
      <dc:date>2010-03-26T15:02:32Z</dc:date>
    </item>
  </channel>
</rss>

