- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Audit trail/log examples?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 06:55 AM
тАО09-11-2002 06:55 AM
Could anyone please point me to some sample output from process auditing?
I'm looking at turning this on, but I'd like to know a little better what I can expect to see. I'm hoping that this will provide a nice compliment (replacement?) for process accounting - and help me better answer the question, "What was running at the time?"
Thanks.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 07:08 AM
тАО09-11-2002 07:08 AM
Re: Audit trail/log examples?
http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x33b9854994d9d4118fef0090279cd0f9,00.html
live free or die
harry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 07:12 AM
тАО09-11-2002 07:12 AM
Re: Audit trail/log examples?
live free or die
harry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 07:17 AM
тАО09-11-2002 07:17 AM
Re: Audit trail/log examples?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 07:49 AM
тАО09-11-2002 07:49 AM
SolutionI've attached a text file showing output from the audisp command with a minimal amount of events being audited. The audevent command at the top of the file shows what was setup. I then attempted to login with an invalid account, followed by logging in and then chmod'ing a file.
If you're after documentation for auditing I'd start with the audit(5) man page, also http://docs.hp.com has further info.
regards,
Darren.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 09:44 AM
тАО09-11-2002 09:44 AM
Re: Audit trail/log examples?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-11-2002 08:02 PM
тАО09-11-2002 08:02 PM
Re: Audit trail/log examples?
is easy. 'audevent -PFE' will select all record types for both system calls and self-auditing records. You don't have to do anything special (such as with audusr) to select all users. It would be a good idea to be sure you are current on patches for inetd and audisp. Also keep in mind that auditing everything can chew up an impressive amount of disk space. Be careful which file system you use to hold the audit logs, so you don't create full disk headaches for yourself.
One more caveat:
Processes may not be properly audited unless they are started AFTER auditing is turned on.
This is as designed but can be confusing.
See /etc/rc.config.d/auditing to enable auditing automatically as the system boots.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-12-2002 04:30 AM
тАО09-12-2002 04:30 AM
Re: Audit trail/log examples?
the auditing switches to a 2nd logfile upon a certain (configurable) size. If this is full too this could mean that events cannot be logged anymore. To prevent this root is the only user who can still work in this situation.
take care, Tom
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-12-2002 07:08 AM
тАО09-12-2002 07:08 AM
Re: Audit trail/log examples?
Tens/Hundreds of GB? I'm trying to get a feel for how much space I'd need for a week's worth of information on a very busy system.
Thanks, all!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-12-2002 07:16 AM
тАО09-12-2002 07:16 AM
Re: Audit trail/log examples?
with auditing turned on, the space required will vary, based on number of events/users audited and events occuring.
Prefer creating a seperate VG/file system for auditing and mount/link in /.secure/etc
Thanks.
Prashant.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-12-2002 08:09 AM
тАО09-12-2002 08:09 AM
Re: Audit trail/log examples?
since it depends so much on machine size/speed/load, applications you run, which users/events are selected for auditing, etc. Planning for something in the range of hundreds of megabytes to 5 or so GB on a
dedicated logical volume is probably a good place to start. Once you get some real data for your system you can adjust up or down as needed.