<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auditing Trusted mode in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297861#M746161</link>
    <description>You can audit a event that you want. Like delete etc.&lt;BR /&gt;&lt;BR /&gt;man audevent. audevent -e "event_you_want_to_monitor"&lt;BR /&gt;&lt;BR /&gt;Anil</description>
    <pubDate>Mon, 07 Jun 2004 10:18:30 GMT</pubDate>
    <dc:creator>RAC_1</dc:creator>
    <dc:date>2004-06-07T10:18:30Z</dc:date>
    <item>
      <title>Auditing Trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297860#M746160</link>
      <description>I have trusted mode installed and configured on many HPUX 11i workstations.  We are have a security requirement to audit the systems each week.  We are having trouble keeping up with the large amount of log entries.  We ultimately would like to automate the auditing or at least get the log entries into a more human readable form.  Is there a way to accomplish this without writing an entire application?</description>
      <pubDate>Mon, 07 Jun 2004 10:16:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297860#M746160</guid>
      <dc:creator>Randy Gelineau</dc:creator>
      <dc:date>2004-06-07T10:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing Trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297861#M746161</link>
      <description>You can audit a event that you want. Like delete etc.&lt;BR /&gt;&lt;BR /&gt;man audevent. audevent -e "event_you_want_to_monitor"&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Mon, 07 Jun 2004 10:18:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297861#M746161</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2004-06-07T10:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing Trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297862#M746162</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Auditing doesn't provide may tools. You need to use 'audisp' command to filter out the events and the users. &lt;BR /&gt;&lt;BR /&gt;Moreover, if you enable all the events, then that is what you will get. My consideration would be to audit the default events -moddac, login, admin and the event modaccess + the system calls execv and execve. The last two system calls may log all the commands executed by the users through shell. &lt;BR /&gt;&lt;BR /&gt;You can probably write an awk script to parse out the 'audisp' output and put it in a human readable format. The first row of the output contains the names of the fields.&lt;BR /&gt;&lt;BR /&gt;You may also want to look at IDS/9000 that you can use to get better format in a centralized location.&lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Jun 2004 10:38:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-trusted-mode/m-p/3297862#M746162</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2004-06-07T10:38:41Z</dc:date>
    </item>
  </channel>
</rss>

