| |
| Figure 2-1 Audit Trail Separated by Host | 21 |
| Figure 2-2 Audit Trail Separated by Server | 22 |
| Figure 2-3 audit_control File Entries | 34 |
| Figure 4-1 Sample device_allocate File | 66 |
| Figure A-1 Typical Audit Record | 78 |
| Figure A-2 arbitrary Token Format | 80 |
| Figure A-3 arg Token Format | 81 |
| Figure A-4 attr Token Format | 81 |
| Figure A-5 exec_args Token Format | 82 |
| Figure A-6 exec_env Token Format | 82 |
| Figure A-7 exit Token Format | 83 |
| Figure A-8 file Token Format | 83 |
| Figure A-9 groups Token Format | 84 |
| Figure A-10 header Token Format | 85 |
| Figure A-11 in_addr Token Format | 85 |
| Figure A-12 ip Token Format | 86 |
| |
| Figure A-13 ipc Token Format | 86 |
| Figure A-14 ipc_perm Token Format | 87 |
| Figure A-15 iport Token Format | 88 |
| Figure A-16 newgroups Token Format | 88 |
| Figure A-17 opaque Token Format | 89 |
| Figure A-18 path Token Format | 89 |
| Figure A-19 process Token Format | 90 |
| Figure A-20 return Token Format | 91 |
| Figure A-21 seq Token Format | 91 |
| Figure A-22 socket Token Format | 92 |
| Figure A-23 socket-inet Token Format | 92 |
| Figure A-24 subject Token Format | 93 |
| Figure A-25 text Token Format | 93 |
| Figure A-26 trailer Token Format | 94 |