<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auditing Problem in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-problem/m-p/3340270#M746759</link>
    <description>I have auditing turned on the monitor delete events as well as chmods.  There are a couple of problems I have found.&lt;BR /&gt;&lt;BR /&gt;1. While it does monitor for rmdir's just fine, I don't see where it is monitoring for rm's.  If this is under a different name (ie. the system call) what is it?&lt;BR /&gt;&lt;BR /&gt;2.  When it displays the "Path" to the file that was modified/deleted, it only shows what the user typed in.  If they don't specify a full path, the information is pretty much useless.  Anyone know if it is possible to have auditing always display a full path?&lt;BR /&gt;&lt;BR /&gt;3.  Is it possible to monitor events/system calls from root.  I noticed a bunch of events created by User=????????.  Is that root or the system itself?&lt;BR /&gt;&lt;BR /&gt;Any insight that can be provided would be very much appreciated.</description>
    <pubDate>Sat, 24 Jul 2004 14:12:37 GMT</pubDate>
    <dc:creator>James Candalino</dc:creator>
    <dc:date>2004-07-24T14:12:37Z</dc:date>
    <item>
      <title>Auditing Problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-problem/m-p/3340270#M746759</link>
      <description>I have auditing turned on the monitor delete events as well as chmods.  There are a couple of problems I have found.&lt;BR /&gt;&lt;BR /&gt;1. While it does monitor for rmdir's just fine, I don't see where it is monitoring for rm's.  If this is under a different name (ie. the system call) what is it?&lt;BR /&gt;&lt;BR /&gt;2.  When it displays the "Path" to the file that was modified/deleted, it only shows what the user typed in.  If they don't specify a full path, the information is pretty much useless.  Anyone know if it is possible to have auditing always display a full path?&lt;BR /&gt;&lt;BR /&gt;3.  Is it possible to monitor events/system calls from root.  I noticed a bunch of events created by User=????????.  Is that root or the system itself?&lt;BR /&gt;&lt;BR /&gt;Any insight that can be provided would be very much appreciated.</description>
      <pubDate>Sat, 24 Jul 2004 14:12:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-problem/m-p/3340270#M746759</guid>
      <dc:creator>James Candalino</dc:creator>
      <dc:date>2004-07-24T14:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing Problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/auditing-problem/m-p/3340271#M746760</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;2. I believe you can only have the path as typed by the user.  Perhaps monitoring chdir() may help.&lt;BR /&gt;&lt;BR /&gt;3. Yes, root can be audited - use audusr to check whether this has been set.  The user=?????? comes from situations where the user cannot be determined.  I think login might be one of these situations, as the user isn't known when the command starts.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
      <pubDate>Mon, 26 Jul 2004 06:41:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/auditing-problem/m-p/3340271#M746760</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2004-07-26T06:41:49Z</dc:date>
    </item>
  </channel>
</rss>

