HPE GreenLake Administration
- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Enabling audit logs and audit trails
Operating System - HP-UX
1834456
Members
3077
Online
110067
Solutions
Forums
Categories
Company
Local Language
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 05:00 AM
07-25-2006 05:00 AM
Enabling audit logs and audit trails
Can you please let me know the procedure to enable the following audit events. Is this done through the SAM tool? The SAM tool, has an option to enable audit events but I am not sure if that would enable all the below mentioned events or more. Also, can you tell me what is required to enable audit trails. Please let me know at the earliest.
a. Successful and unsuccessful login attempts.
b. Successful and unsuccessful attempts to switch to another user's account (where applicable).
c. Logoffs.
d. User attempts to access files or resources outside their privilege level.
e. User access to all privileged files and/or processes.
f. Operating system configuration changes.
g. Operating system program changes.
h. All changes, that can feasibly be captured, to system hardware and software.
i. All security related changes, including adding users.
j. Failures for computer, program, communications, and operations.
k. Starting and stopping of audit logging.
a. Successful and unsuccessful login attempts.
b. Successful and unsuccessful attempts to switch to another user's account (where applicable).
c. Logoffs.
d. User attempts to access files or resources outside their privilege level.
e. User access to all privileged files and/or processes.
f. Operating system configuration changes.
g. Operating system program changes.
h. All changes, that can feasibly be captured, to system hardware and software.
i. All security related changes, including adding users.
j. Failures for computer, program, communications, and operations.
k. Starting and stopping of audit logging.
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 05:12 AM
07-25-2006 05:12 AM
Re: Enabling audit logs and audit trails
You need to spend some time with the man page for audit and the rest of the "SEE ALSO"s that it mentions.
Pete
Pete
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-25-2006 05:18 AM
07-25-2006 05:18 AM
Re: Enabling audit logs and audit trails
Some of these are already done without auditing. See last, lastb, who.
Some could be configured outside of auditing, for example running a cron job that provides an swlist > /tmp/swlist.`date +'%m%d%H%M' and also a print_mainifest in the same manner. print_manifest is part of Ignite, a free download for the software depot.
For information on auditing see http://docs.hp.com/en/B2355-90950/ch08s09.html
Some could be configured outside of auditing, for example running a cron job that provides an swlist > /tmp/swlist.`date +'%m%d%H%M' and also a print_mainifest in the same manner. print_manifest is part of Ignite, a free download for the software depot.
For information on auditing see http://docs.hp.com/en/B2355-90950/ch08s09.html
"Downtime is a Crime."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-26-2006 08:02 AM
07-26-2006 08:02 AM
Re: Enabling audit logs and audit trails
If you have 11iv2 (11.23) systems, you can use Standard Mode Audit.
http://www.docs.hp.com/en/5991-1821/ch06s03.html
List of auditable events:
http://www.docs.hp.com/en/B2355-60105/audevent.1M.html
If a real-time response/notification capability is a requirement, you might also want to take a look at HPUX Host IDS to monitor a), b), c), g) and some of d), e), h), and i). HIDS monitors activity using the audit records produced by the same kernel audit subsystem that produces audit records for Standard Mode Audit.
http://h20338.www2.hp.com/hpux11i/cache/324806-0-0-0-121.html
Pierre
http://www.docs.hp.com/en/5991-1821/ch06s03.html
List of auditable events:
http://www.docs.hp.com/en/B2355-60105/audevent.1M.html
If a real-time response/notification capability is a requirement, you might also want to take a look at HPUX Host IDS to monitor a), b), c), g) and some of d), e), h), and i). HIDS monitors activity using the audit records produced by the same kernel audit subsystem that produces audit records for Standard Mode Audit.
http://h20338.www2.hp.com/hpux11i/cache/324806-0-0-0-121.html
Pierre
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Events and news
Customer resources
© Copyright 2025 Hewlett Packard Enterprise Development LP