Operating System - HP-UX
1753808 Members
7506 Online
108805 Solutions
New Discussion юеВ

Re: enable rm in delete event (Trusted System)

 
SOLVED
Go to solution
Aneesh Mohan
Honored Contributor

enable rm in delete event (Trusted System)

Hi ,

Query regarding auditing events on trusted system.

I couldn`t able to enable rm in audited event ,for tracing the users who are all using rm command to remove files/directories.I can see rmdir which is comming default in "delete" audited event .

Please do let me know if it is possible on 11.11 .

fyi:-

# uname -r
B.11.11

# what /usr/lbin/tsconvert
/usr/lbin/tsconvert:
$Revision: @(#) tsconvert R11.11_BL2007_0412_1 PATCH_11.11 PHCO_36329

4 REPLIES 4
Aneesh Mohan
Honored Contributor

Re: enable rm in delete event (Trusted System)


Hi all ,

Any inputs to my questions.

Thanks in advance .


ANEESH
doug hosking
Esteemed Contributor
Solution

Re: enable rm in delete event (Trusted System)

The 'unlink' system call is what really causes files to be deleted by the rm command. Do you have that enabled in your audit configuration? If so, then you should see unlink records, which will show you which files were deleted (or attempted to be deleted).
whiteknight
Honored Contributor

Re: enable rm in delete event (Trusted System)

Aneesh,

See this url on the audited event

http://docs.hp.com/en/B2355-90950/ch08s09.html?btnNext=next%A0%BB


hope this help
WK
Problem never ends, you must know how to fix it
Aneesh Mohan
Honored Contributor

Re: enable rm in delete event (Trusted System)

Many thanks Doug&Wk.

Enabled unlink,now I can get the rm information .But the path for the file is not listing ,is there any way to trace the path ?


Thanks again,
Aneesh