1837242 Members
4403 Online
110115 Solutions
New Discussion

interpret log of audit

 
Jairo Campana
Trusted Contributor

interpret log of audit

Hello , I implement the security in may system
convert trusted and turn on the audit
as I interpret the information of log of audit
a manual exists?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 020110 10:33:39 3314 S 15 2618 -1 0 0
[ Event=chmod; User=????????; Real Grp=root; Eff.Grp=root; ]
x x RETURN_VALUE 1 = 0; PARAM #1 (file path) = 0 (cnode);
0x40000003(dev); 1509(inode); (path) = /etc/opt/resmon/log/reslog.html PARAM #2 (int) = 420

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
020110 10:33:48 3318 S 57 3016 -1 0 0
[ Event=utssys; User=????????; Real Grp=root; Eff.Grp=root; ]
RETURN_VALUE 1 = 0; PARAM #1 (addr of char) = 2139038080 x
PARAM #2 (int) =0 PARAM #3 (int) = 0

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ x
x x 020110 10:37:30 4619 S 57 4617 -1 0 0 x
x x [ Event=utssys; User=????????; Real Grp=root; Eff.Grp=root; ] x
x x x
x x RETURN_VALUE 1 = 0; x
x x PARAM #1 (addr of char) = 2139038048 x
x x PARAM #2 (int) = 0 x
x x PARAM #3 (int) = 0

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ x
x x 020110 10:33:07 3175 S 15 2618 -1 0 0 x
x x [ Event=chmod; User=????????; Real Grp=root; Eff.Grp=root; ] x
x x x
x x RETURN_VALUE 1 = 0; x
x x PARAM #1 (file path) = 0 (cnode); x
x x 0x40000003 (dev); x
x x 1509 (inode); x
x x (path) = /etc/opt/resmon/log/reslog.html x
x x PARAM #2 (int) = 420


020110 10:24:29 668 S 57 696 13 103 20 ^x
x x [ Event=utssys; User=vantive; Real Grp=users; Eff.Grp=users; ] x
x x x
x x RETURN_VALUE 1 = 0; x
x x PARAM #1 (addr of char) = 2139055232 x
x x PARAM #2 (int) = 65 x
x x PARAM #3 (int) = 5


thanks
legionx