<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit trail/log examples? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804286#M754384</link>
    <description>Capturing all records for all processes&lt;BR /&gt;is easy. 'audevent -PFE' will select all record types for both system calls and self-auditing records.  You don't have to do anything special (such as with audusr) to select all users. It would be a good idea to be sure you are current on patches for inetd and audisp. Also keep in mind that auditing everything can chew up an impressive amount of disk space.  Be careful which file system you use to hold the audit logs, so you don't create full disk headaches for yourself.&lt;BR /&gt;&lt;BR /&gt;One more caveat:&lt;BR /&gt;Processes may not be properly audited unless they are started AFTER auditing is turned on.&lt;BR /&gt;This is as designed but can be confusing.&lt;BR /&gt;See /etc/rc.config.d/auditing to enable auditing automatically as the system boots.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 12 Sep 2002 03:02:02 GMT</pubDate>
    <dc:creator>doug hosking</dc:creator>
    <dc:date>2002-09-12T03:02:02Z</dc:date>
    <item>
      <title>Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804280#M754378</link>
      <description>Hi, folks.&lt;BR /&gt;&lt;BR /&gt;Could anyone please point me to some sample output from process auditing?&lt;BR /&gt;&lt;BR /&gt;I'm looking at turning this on, but I'd like to know a little better what I can expect to see.  I'm hoping that this will provide a nice compliment (replacement?) for process accounting - and help me better answer the question, "What was running at the time?"&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Wed, 11 Sep 2002 13:55:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804280#M754378</guid>
      <dc:creator>A. Daniel King_1</dc:creator>
      <dc:date>2002-09-11T13:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804281#M754379</link>
      <description>This thread has a great answer from JRF:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x33b9854994d9d4118fef0090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x33b9854994d9d4118fef0090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Wed, 11 Sep 2002 14:08:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804281#M754379</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-09-11T14:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804282#M754380</link>
      <description>Actually I should say ANSWERS as in multiple!&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Wed, 11 Sep 2002 14:12:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804282#M754380</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-09-11T14:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804283#M754381</link>
      <description>Ahhh.  The very docs I used to set up _accouting_.  I am interested more specifically in auditing, i.e., man audsys.</description>
      <pubDate>Wed, 11 Sep 2002 14:17:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804283#M754381</guid>
      <dc:creator>A. Daniel King_1</dc:creator>
      <dc:date>2002-09-11T14:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804284#M754382</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I've attached a text file showing output from the audisp command with a minimal amount of events being audited.  The audevent command at the top of the file shows what was setup.  I then attempted to login with an invalid account, followed by logging in and then chmod'ing a file.&lt;BR /&gt;&lt;BR /&gt;If you're after documentation for auditing I'd start with the audit(5) man page, also &lt;A href="http://docs.hp.com" target="_blank"&gt;http://docs.hp.com&lt;/A&gt; has further info.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
      <pubDate>Wed, 11 Sep 2002 14:49:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804284#M754382</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2002-09-11T14:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804285#M754383</link>
      <description>Fantastic!  Can the user definable categories can easily be set to capture all processes?</description>
      <pubDate>Wed, 11 Sep 2002 16:44:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804285#M754383</guid>
      <dc:creator>A. Daniel King_1</dc:creator>
      <dc:date>2002-09-11T16:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804286#M754384</link>
      <description>Capturing all records for all processes&lt;BR /&gt;is easy. 'audevent -PFE' will select all record types for both system calls and self-auditing records.  You don't have to do anything special (such as with audusr) to select all users. It would be a good idea to be sure you are current on patches for inetd and audisp. Also keep in mind that auditing everything can chew up an impressive amount of disk space.  Be careful which file system you use to hold the audit logs, so you don't create full disk headaches for yourself.&lt;BR /&gt;&lt;BR /&gt;One more caveat:&lt;BR /&gt;Processes may not be properly audited unless they are started AFTER auditing is turned on.&lt;BR /&gt;This is as designed but can be confusing.&lt;BR /&gt;See /etc/rc.config.d/auditing to enable auditing automatically as the system boots.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Sep 2002 03:02:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804286#M754384</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2002-09-12T03:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804287#M754385</link>
      <description>in addition to Doug: &lt;BR /&gt;the auditing switches to a 2nd logfile upon a certain (configurable) size. If this is full too this could mean that events cannot be logged anymore. To prevent this root is the only user who can still work in this situation.&lt;BR /&gt;&lt;BR /&gt;take care, Tom</description>
      <pubDate>Thu, 12 Sep 2002 11:30:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804287#M754385</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2002-09-12T11:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804288#M754386</link>
      <description>Could you define - or get me in the ballpark - for an "impressive amount of disk space"?&lt;BR /&gt;&lt;BR /&gt;Tens/Hundreds of GB?  I'm trying to get a feel for how much space I'd need for a week's worth of information on a very busy system.&lt;BR /&gt;&lt;BR /&gt;Thanks, all!</description>
      <pubDate>Thu, 12 Sep 2002 14:08:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804288#M754386</guid>
      <dc:creator>A. Daniel King_1</dc:creator>
      <dc:date>2002-09-12T14:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804289#M754387</link>
      <description>HI&lt;BR /&gt;with auditing turned on, the space required will vary, based on number of events/users audited and events occuring. &lt;BR /&gt;Prefer creating a seperate VG/file system for auditing and mount/link in /.secure/etc&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;Prashant.</description>
      <pubDate>Thu, 12 Sep 2002 14:16:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804289#M754387</guid>
      <dc:creator>Deshpande Prashant</dc:creator>
      <dc:date>2002-09-12T14:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Audit trail/log examples?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804290#M754388</link>
      <description>Questions re disk space are hard to answer,&lt;BR /&gt;since it depends so much on machine size/speed/load, applications you run, which users/events are selected for auditing, etc.  Planning for something in the range of hundreds of megabytes to 5 or so GB on a&lt;BR /&gt;dedicated logical volume is probably a good place to start.  Once you get some real data for your system you can adjust up or down as needed.&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Sep 2002 15:09:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-trail-log-examples/m-p/2804290#M754388</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2002-09-12T15:09:09Z</dc:date>
    </item>
  </channel>
</rss>

