| |
Process Audit Characteristics | 14 |
How the Audit Trail is Created | 15 |
| ...The audit_data File | 16 |
| ...The Audit Daemon's Role | 16 |
| ...What Makes a Directory Suitable | 17 |
| ...Keeping Audit Files Manageable | 17 |
The audit_warn Script | 17 |
Using the auditreduce Command | 19 |
Controlling Audit Costs | 22 |
Auditing Normal Users | 25 |
Auditing Efficiently | 25 |
Learning About the Audit Trail | 26 |
| ...More about the Audit Files | 27 |
| ...Handling Non-active Files Marked not-terminated | 29 |
Creating Audit Partitions and Exporting Them | 30 |
Planning Audit Configuration | 33 |
Preventing Audit Trail Overflow | 36 |
The auditconfig Command | 37 |
Setting Audit Policies | 39 |
Changing Audit Event to Class Mappings and Adding Events | 40 |
Changing Class Definitions | 40 |
4. Audit Trail Analysis | 41 |
Auditing Features | 41 |
| |
| Tools for Merging, Selecting, Viewing, and Interpreting Audit |
| ......Records | 42 |
| Audit Record Format | 43 |
| Using the auditreduce Command | 54 |
| ...How auditreduce Helps In a Distributed System | 54 |
| ...auditreduce Examples | 55 |
| ...Other Useful auditreduce Options | 56 |
| Using praudit | 57 |
5. Device Allocation | 59 |
| Risks Associated with Device Use | 59 |
| Components of the Device Allocation Mechanism | 60 |
| Using the Device Allocation Utilities | 60 |
| The Allocate Error State | 61 |
| The device_maps File | 62 |
| The device_allocate File | 63 |
| Device Clean Scripts | 65 |
| ...Object Reuse | 66 |
| ...Writing New Device Clean Scripts | 67 |
| Setting Up Lock Files | 68 |
| Managing and Adding Devices | 71 |
| Using Device Allocations | 72 |
A. Audit Record Descriptions | 75 |
| Audit Record Structure | 75 |
| Audit Token Structure | 76 |