1848254 Members
7913 Online
104022 Solutions
New Discussion

Re: set up auditing

 
Gary_O
Frequent Advisor

set up auditing

I would like to set up auditing to try and see why files/directories might be getting deleted. Also, seems I have ghost atjobs running (the #########.a file was manually removed from the atjobs directory, instead of using at -r)

What items should I audit for?
3 REPLIES 3
Steven E. Protter
Exalted Contributor

Re: set up auditing

You can make your system trusted with the tsconvert command or

as root

sam
auditing and security

You should be able to turn on trusted system there.

There are impacts on cron users and such and the step should be planned carefully.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Gary_O
Frequent Advisor

Re: set up auditing

I do not want to complicate matters.

There are a LOT of events/calls that can be monitored. Can someone help me pinpoint the most pertinent for my needs?

And what is the impact on use of cron?
Sundar_7
Honored Contributor

Re: set up auditing

Hi,

Audit the events delete and the system call unlink.

Sundar
Learn What to do ,How to do and more importantly When to do ?