- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: /.secure/etc/audfile1 size restriction
Operating System - HP-UX
1748137
Members
3644
Online
108758
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-13-2010 03:25 AM
тАО08-13-2010 03:25 AM
/.secure/etc/audfile1 size restriction
Hi
Recently we installed a s/w ServerSensor70_HP-UX_SR4_1.depot and wanted to start auditing.
cat /etc/rc.config.d/auditing
---
---
---
AUDITING=1
PRI_AUDFILE=/.secure/etc/audfile1
PRI_SWITCH=1000
SEC_AUDFILE=/.secure/etc/audfile2
SEC_SWITCH=1000
AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin"
AUDEVENT_ARGS2=""
AUDEVENT_ARGS3=""
AUDEVENT_ARGS4=""
AUDOMON_ARGS="-p 20 -t 1 -w 90"
#
#
# cd /.secure/etc
#
# ll
total 22320
-rw------- 1 root root 3462844 Aug 13 11:25 audfile1 (see this file size!!)
-rw------- 1 root sys 5134197 Jul 20 15:22 audfile2 (see this file size!!)
-rw------- 1 root root 31 Aug 9 17:10 audnames
#
# cat audnames
/.secure/etc/audfile1,1000
*,0
#
Console is full of these errors/messages
current audit file size is 3384 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
I thought in audnames file this line
/.secure/etc/audfile1,1000
restricts the size of audfile1 to 1000kb.
But it is not restricting!
Also, I just now added a line(audfile2) in audnames file. This is just fyi
# cat audnames
/.secure/etc/audfile1,1000
/.secure/etc/audfile2,1000
*,0
#
My main intention is to restrict the file size of audfile* to a particular size...say 1 MB
In the other threads, I saw suggestions to do this via SAM, but I couldn't do this as I cannot see any such options in SAM/SMH
# uname -a
HP-UX B.11.23 U ia64 0263711056 unlimited-user license
#
Can somebody help me in acheiving this..thanks
Recently we installed a s/w ServerSensor70_HP-UX_SR4_1.depot and wanted to start auditing.
cat /etc/rc.config.d/auditing
---
---
---
AUDITING=1
PRI_AUDFILE=/.secure/etc/audfile1
PRI_SWITCH=1000
SEC_AUDFILE=/.secure/etc/audfile2
SEC_SWITCH=1000
AUDEVENT_ARGS1="-P -F -e moddac -e login -e admin"
AUDEVENT_ARGS2=""
AUDEVENT_ARGS3=""
AUDEVENT_ARGS4=""
AUDOMON_ARGS="-p 20 -t 1 -w 90"
#
#
# cd /.secure/etc
#
# ll
total 22320
-rw------- 1 root root 3462844 Aug 13 11:25 audfile1 (see this file size!!)
-rw------- 1 root sys 5134197 Jul 20 15:22 audfile2 (see this file size!!)
-rw------- 1 root root 31 Aug 9 17:10 audnames
#
# cat audnames
/.secure/etc/audfile1,1000
*,0
#
Console is full of these errors/messages
current audit file size is 3384 kilobytes!!!
an attempt to switch to the backup file failed.
Must specify a backup file now !
I thought in audnames file this line
/.secure/etc/audfile1,1000
restricts the size of audfile1 to 1000kb.
But it is not restricting!
Also, I just now added a line(audfile2) in audnames file. This is just fyi
# cat audnames
/.secure/etc/audfile1,1000
/.secure/etc/audfile2,1000
*,0
#
My main intention is to restrict the file size of audfile* to a particular size...say 1 MB
In the other threads, I saw suggestions to do this via SAM, but I couldn't do this as I cannot see any such options in SAM/SMH
# uname -a
HP-UX
#
Can somebody help me in acheiving this..thanks
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-13-2010 07:36 AM
тАО08-13-2010 07:36 AM
Re: /.secure/etc/audfile1 size restriction
>
PRI_AUDFILE=/.secure/etc/audfile1
/.secure is a very, very bad place for auditing logs. Yes, know it's the default but you never put logs, expecially massively large logs from auditing into the / directory.
> /.secure/etc/audfile1,1000
1 MB is way, way too small for an audit log. Auditing limits can be very carefully adjusted so they do not grow to gigabytes in size, but I would start your logs in a big directory like /var and create a .secure directory there. Then increase the log sizes to 10-20 MB and restart auditing. Now monitor the size of the logs. Once you are comfortable with the growth, you can adjust the size. Note that you only have two logs. If one fills the previous log is erased and a new log is started. Ideally, the maximum log size should last for several days and that may mean your logs must be 100-300 MB.
Bill Hassell, sysadmin
PRI_AUDFILE=/.secure/etc/audfile1
/.secure is a very, very bad place for auditing logs. Yes, know it's the default but you never put logs, expecially massively large logs from auditing into the / directory.
> /.secure/etc/audfile1,1000
1 MB is way, way too small for an audit log. Auditing limits can be very carefully adjusted so they do not grow to gigabytes in size, but I would start your logs in a big directory like /var and create a .secure directory there. Then increase the log sizes to 10-20 MB and restart auditing. Now monitor the size of the logs. Once you are comfortable with the growth, you can adjust the size. Note that you only have two logs. If one fills the previous log is erased and a new log is started. Ideally, the maximum log size should last for several days and that may mean your logs must be 100-300 MB.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-17-2010 01:24 AM
тАО08-17-2010 01:24 AM
Re: /.secure/etc/audfile1 size restriction
Hello Bill
Sorry for late response.
Okay, I will try to create .secure/etc/audfile1 in /var
And I think I need to mention the new path in /.secure/etc/audnames
Let us say I want to change the max size of audfile1 to 300MB, then do I need to mention that in audnames? or somewhere else?
Now, my main intention is to restrict the audfile1 & audfile2 to 300MB
then would it be like this?
# cat audnames
/.secure/etc/audfile1,300000
/.secure/etc/audfile2,300000
*,0
#
I think I also need to do something to audit only the newly installed software and turn off auditing of other softwares..
Sorry for late response.
Okay, I will try to create .secure/etc/audfile1 in /var
And I think I need to mention the new path in /.secure/etc/audnames
Let us say I want to change the max size of audfile1 to 300MB, then do I need to mention that in audnames? or somewhere else?
Now, my main intention is to restrict the audfile1 & audfile2 to 300MB
then would it be like this?
# cat audnames
/.secure/etc/audfile1,300000
/.secure/etc/audfile2,300000
*,0
#
I think I also need to do something to audit only the newly installed software and turn off auditing of other softwares..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-20-2010 03:30 AM
тАО08-20-2010 03:30 AM
Re: /.secure/etc/audfile1 size restriction
audfile sizes should be high
both the file names should be mentioned in audnames file
both the file names should be mentioned in audnames file
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
News and Events
Support
© Copyright 2024 Hewlett Packard Enterprise Development LP