<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit Logs in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566399#M759233</link>
    <description>Use this command to display the information contained in audsys logs files:&lt;BR /&gt;&lt;BR /&gt;audisp [options flags] audit_filename&lt;BR /&gt;&lt;BR /&gt;Use the options flags to filter the output:&lt;BR /&gt;&lt;BR /&gt;-u username, -e eventname, -c syscall, -l ttyid, -t start_time, -s stop_time, ...&lt;BR /&gt;&lt;BR /&gt;Please, consult man page for more info. Thanks.</description>
    <pubDate>Mon, 20 Aug 2001 06:13:17 GMT</pubDate>
    <dc:creator>Manuel P. Ron</dc:creator>
    <dc:date>2001-08-20T06:13:17Z</dc:date>
    <item>
      <title>Audit Logs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566398#M759232</link>
      <description>Anyone write custom scripts that filter the audit logs?  If so can I get an example.  I am looking to make the audit log output more readable i.e. so none unix people can read them and somewhat understand what is going on, like user xxx logged on and then su'd to user yyy and then logged off.</description>
      <pubDate>Thu, 16 Aug 2001 23:45:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566398#M759232</guid>
      <dc:creator>Mike Burk</dc:creator>
      <dc:date>2001-08-16T23:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Logs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566399#M759233</link>
      <description>Use this command to display the information contained in audsys logs files:&lt;BR /&gt;&lt;BR /&gt;audisp [options flags] audit_filename&lt;BR /&gt;&lt;BR /&gt;Use the options flags to filter the output:&lt;BR /&gt;&lt;BR /&gt;-u username, -e eventname, -c syscall, -l ttyid, -t start_time, -s stop_time, ...&lt;BR /&gt;&lt;BR /&gt;Please, consult man page for more info. Thanks.</description>
      <pubDate>Mon, 20 Aug 2001 06:13:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566399#M759233</guid>
      <dc:creator>Manuel P. Ron</dc:creator>
      <dc:date>2001-08-20T06:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Audit Logs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566400#M759234</link>
      <description>On Debian GNU/Linux you have logcheck (&lt;A href="http://packages.debian.org/cgi-bin/search_packages.pl?keywords=logcheck&amp;amp;searchon=names&amp;amp;subword=1&amp;amp;version=all&amp;amp;release=all)" target="_blank"&gt;http://packages.debian.org/cgi-bin/search_packages.pl?keywords=logcheck&amp;amp;searchon=names&amp;amp;subword=1&amp;amp;version=all&amp;amp;release=all)&lt;/A&gt; and that application can incremental scan and mail the results of a check on logfiles to a mailaddress. And you can extend the search-patterns. A little note, the logcheck in testing and unstable have more patterns then logcheck in stable.&lt;BR /&gt;&lt;BR /&gt;-Hans</description>
      <pubDate>Fri, 07 Sep 2001 10:06:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/audit-logs/m-p/2566400#M759234</guid>
      <dc:creator>Joe Doe Sr</dc:creator>
      <dc:date>2001-09-07T10:06:59Z</dc:date>
    </item>
  </channel>
</rss>

