HPE GreenLake Administration
- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- auditing on HP-UX 11iv2 change log does not occur
Operating System - HP-UX
1834461
Members
3058
Online
110067
Solutions
Forums
Categories
Company
Local Language
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-24-2009 11:48 AM
02-24-2009 11:48 AM
auditing on HP-UX 11iv2 change log does not occur
I can not find any documentation on implementing the auditing features besides the man pages and I can not seem to get an automated change of the auditing log to occur.
Configuring /etc/rc.config.d/auditing to have:
AUDITING=1
PRI_AUDFILE=/var/.audit/audtrail-pri
PRI_SWITCH=4096
SEC_AUDFILE=/var/.audit/audtrail-sec
SEC_SWITCH=4096
#AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin"
AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin -e delete -e removable -e open"
AUDEVENT_ARGS2=""
AUDEVENT_ARGS3=""
AUDEVENT_ARGS4=""
AUDOMON_ARGS="-p 20 -t 1 -w 90"
After /var/.audit/audtrail-sec is over 4096KBs
the audomon starts giving warnings every minute.
It would seem that a audsys command needs to be run to give a new file not Primary or Secondary to write to.
How is this automated?
On HP-UX 11i v3 you leave secondary blank and it appends yyyymmdd_hhmm to the primary file name and continues on nicely.
Some output
pvwpro03:/root # audsys
auditing system is currently on
current file: /var/.audit/audtrail-sec
next file: none
statistics- afs Kb used Kb avail % fs Kb used Kb avail %
current file: 4096 12478 -204 10485760 3327224 68
next file: none
messages
Must specify a backup file now !
current audit file size is 12476 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
current audit file size is 12487 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
It seems to perhaps need a cron job but I would like to see a documented procedure if possible.
Thanks,
Wayne
Configuring /etc/rc.config.d/auditing to have:
AUDITING=1
PRI_AUDFILE=/var/.audit/audtrail-pri
PRI_SWITCH=4096
SEC_AUDFILE=/var/.audit/audtrail-sec
SEC_SWITCH=4096
#AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin"
AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin -e delete -e removable -e open"
AUDEVENT_ARGS2=""
AUDEVENT_ARGS3=""
AUDEVENT_ARGS4=""
AUDOMON_ARGS="-p 20 -t 1 -w 90"
After /var/.audit/audtrail-sec is over 4096KBs
the audomon starts giving warnings every minute.
It would seem that a audsys command needs to be run to give a new file not Primary or Secondary to write to.
How is this automated?
On HP-UX 11i v3 you leave secondary blank and it appends yyyymmdd_hhmm to the primary file name and continues on nicely.
Some output
pvwpro03:/root # audsys
auditing system is currently on
current file: /var/.audit/audtrail-sec
next file: none
statistics- afs Kb used Kb avail % fs Kb used Kb avail %
current file: 4096 12478 -204 10485760 3327224 68
next file: none
messages
Must specify a backup file now !
current audit file size is 12476 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
current audit file size is 12487 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
It seems to perhaps need a cron job but I would like to see a documented procedure if possible.
Thanks,
Wayne
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-24-2009 12:26 PM
02-24-2009 12:26 PM
Re: auditing on HP-UX 11iv2 change log does not occur
Shalom,
This appears to be a trusted system.
Trusted systems default configuration is to the root filesystem, which is pretty easy to fill up.
I recommend redirecting these logs to a mounted file system and changing your rotation configuration.
Here is the doc
http://docs.hp.com/en/4AA0-4052ENW/4AA0-4052ENW.pdf
SEP
This appears to be a trusted system.
Trusted systems default configuration is to the root filesystem, which is pretty easy to fill up.
I recommend redirecting these logs to a mounted file system and changing your rotation configuration.
Here is the doc
http://docs.hp.com/en/4AA0-4052ENW/4AA0-4052ENW.pdf
SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-25-2009 08:00 AM
02-25-2009 08:00 AM
Re: auditing on HP-UX 11iv2 change log does not occur
Did you send me the right PDF?
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Events and news
Customer resources
© Copyright 2025 Hewlett Packard Enterprise Development LP