Contained Within
Find More Documentation
Featured Support Resources
| PDF로 이 문서 다운로드
Index
Symbols
| |
| - audit flag prefix | 10 to 11 |
| # for comments in files | 65, 67 |
| * indevice_allocate file | 67, 68 |
| + audit flag prefix | 10 to 11 |
| \ ending file lines | 65, 67 |
| ^- audit flag prefix | 11 |
| ^+ audit flag prefix | 11 |
A
| |
| -a option ofauditreduce command | 58 to 59 |
| acct audit record | 96 |
| ad audit flag | 9 |
| adding devices | 74 |
| adjtime audit record | 96 |
| administering auditing |
| .....See also audit records; audit tokens;audit trail |
| .....audit administration account | 35 to 36 |
| .....audit classes |
| ............auditconfig commandoptions | 38 |
| ............changing definitions | 40 |
| ............flags and definitions | 9 to 10 |
| .....mapping events | 7, 40 |
| .....overview | 7 to 8 |
| .....selecting for auditing | 7 |
| audit events |
| .....audit tokens | 46 |
| .....auditconfig commandoptions | 37, 38 |
| .....C library functions | 156 |
| .....categories | 8 |
| .....event-to-system call translationtable | 147 to 152 |
| .....including in audit trail | 7 |
| .....kernel events | 7, 8, 37, 38, 46 |
| .....mapping to classes | 7, 40 |
| .....numbers | 8 |
| .....overview | 7 to 8 |
| .....preselecting | 156 |
| .....record formats and | 45 |
| .....user-level events | 8, 38, 46 |
| audit files | 26 to 30 |
| .....auditreduce command | 20 to 22 |
| .....combining | 20 to 22, 26 |
| .....copying login/logout messagesto single file | 57 to 58 |
| .....directory locations | 27, 31 |
| .....displaying in entirety | 57 |
| .....file token | 50, 83 |
| .....managing size of | 18 |
| |
| ...........minimum free space for filesystems | 12 |
| ...........names | 27 to 29 |
| ...........nonactive files markednot_terminated | 29 to 30, 58 |
| ...........order for opening | 12 |
| ...........overview | 26 to 27 |
| ...........permissions | 32 |
| ...........printing | 57 |
| ...........reducing | 20 to 22, 26 |
| ...........reducing storage-spacerequirements | 23 to 24, 25 |
| ...........switching to new file | 17 |
| ...........time stamps | 28 |
| ....audit flags | 8 to 11 |
| ...........audit_control file line | 12 |
| ...........audit_user file | 13 to 14 |
| ...........auditconfig commandoptions | 38 |
| ...........C library functions | 157 |
| ...........definitions | 9 to 10 |
| ...........machine-wide | 8, 12 |
| ...........overview | 8 |
| ...........policy flags | 39 |
| ...........prefixes | 11 |
| ...........process preselection mask | 15 |
| ...........syntax | 10 |
| ....audit partitions | 30 to 32 |
| ....audit records | 8 |
| ....audit trail creation | 16 to 18 |
| ...........audit daemon's role | 17 |
| ...........audit_data file | 16 |
| ...........directory suitability | 17 |
| ...........managing audit file size | 18 |
| ...........overview | 16 |
| ....audit trail overflow prevention | 36 to 37 |
| ....audit_control file |
| ...........audit_user filemodification | 13 |
| ...........C library functions | 156 |
| ...........overview | 11 to 12 |
| ...........prefixes inflags line | 11 |
| ...........problem with contents | 20 |
| ....audit_user file audit fields | 13 to 14 |
| ....audit_warn script | 16, 18 to 20 |
| .....auditreduce command | 20 to 22, 56 to 59 |
| ............-a option | 58 to 59 |
| ............-b option | 58 to 59 |
| ............capabilities | 56 |
| ............cleaningnot_terminatedfiles | 29 to 30, 58 |
| ............-d option | 57 |
| ............described | 20 to 21, 44, 56 |
| ............distributed systems | 56 |
| ............examples | 57 to 58 |
| ............-O option | 26, 30, 57 to 58 |
| ............options | 20, 58 to 59 |
| ............time stamp use | 28 |
| ............without options | 20 to 22 |
| .....configuration |
| ............audit trail overflowprevention | 36 to 37 |
| ............auditconfig command | 37 to 39 |
| ............overview | 32 to 33 |
| ............planning | 33 to 36 |
| ............setting audit policies | 39 |
| .....cost control | 22 to 24 |
| ............analysis | 23 |
| ............processing time | 23 |
| ............storage | 23 to 24 |
| .....efficiency | 25 to 26 |
| .....normal users | 25 |
| .....overview | 5 to 6 |
| .....process audit characteristics | 14 to 15 |
| ............audit ID | 15 |
| ............audit session ID | 15 |
| ............process preselection mask | 15, 23 to 24 |
| ............terminal ID | 15 |
| .....startup | 6 |
| administrative audit class | 9 |
| all |
| .....audit class | 10 |
| .....audit flag |
| ............caution for using | 10 |
| ............described | 10 |
| .....in user audit fields | 14 |
| |
| allhard string withaudit_warnscript | 19 |
| allocatable devices,See device allocation |
| allocate audit record |
| .....allocate-list devicesuccess | 140 |
| .....deallocate device | 140 |
| .....deallocate device failure | 140 |
| .....device allocate failure | 140 |
| .....device allocate success | 139 |
| allocate command |
| .....See also device allocation |
| .....how the allocate mechanismworks | 71 to 73 |
| .....options | 63 |
| .....using | 75 to 76 |
| allocate error state | 64 |
| allocating devices,See device allocation |
| allsoft string withaudit_warnscript | 19 |
| always-audit flags |
| .....described | 13 to 14 |
| .....process preselection mask | 15 |
| analysis | 43 to 60 |
| .....audit record format | 45 to 55 |
| .....auditing features | 43 to 44 |
| .....auditreduce command | 45, 56 to 59 |
| .....costs | 23 |
| .....praudit command | 45, 59 to 60 |
| .....tools | 44 to 45 |
| ap audit flag | 9 |
| application audit class | 9 |
| arbitrary token | 48 to 49, 79 |
| Archive tape drive clean script | 67 |
| arg token | 49, 81 |
| arge policy |
| .....exec_env token and | 82 |
| .....flag | 39 |
| argv policy |
| .....exec_args token and | 82 |
| .....flag | 39 |
| asterisk (*) indevice_allocate file | 67, 68 |
| at audit record |
| .....at-create crontab | 141 |
| .....at-delete atjob | 141 |
| .....at-permission | 141 |
| attr token | 49 to 50, 81 |
| audio devices |
| .....See also device allocation |
| .....device-clean scripts | 70 |
| audio_clean script | 70 |
| AUDIO_DRAIN ioctl system call | 70 |
| AUDIO_SETINFO ioctl system call | 70 |
| AUDIOGETREG ioctl system call | 70 |
| AUDIOSETREG ioctl system call | 70 |
| audit administration account | 35 to 36 |
| audit attributes.See audit tokens |
| audit audit record | 96 |
| audit classes |
| .....auditconfig command options | 38 |
| .....changing definitions | 40 |
| .....flags and definitions | 9 to 10 |
| .....mapping events | 7, 40 |
| .....overview | 7 to 8 |
| .....selecting for auditing | 7 |
| audit daemon |
| .....audit trail creation | 16, 17 |
| .....audit_startup file | 6 |
| .....audit_warn script |
| ............conditions invoking | 18 to 20 |
| ............described | 16, 18 |
| ............execution of | 17 |
| .....directories suitable to | 17 |
| .....enabling auditing | 6 |
| .....functions | 17 |
| .....order audit files are opened | 12 |
| .....rereading theaudit_controlfile | 12 |
| .....terminating | 16 |
| audit events |
| .....See also audit classes |
| .....audit_event file |
| ............audit event type | 45 |
| ............overview | 7 to 8 |
| .....C library functions | 156 |
| .....categories | 8 |
| |
| .....event-to-system call translationtable | 147 to 152 |
| .....including in audit trail | 7 |
| .....kernel events |
| ............audit tokens | 46 |
| ............auditconfig commandoptions | 37, 38 |
| ............described | 7 |
| .....mapping to classes | 7, 40 |
| .....numbers | 8 |
| .....overview | 7 to 8 |
| .....preselecting | 156 |
| .....record formats and | 45 |
| .....user-level events |
| ............audit tokens | 46 |
| ............auditconfig commandoptions | 38 |
| ............described | 8 |
| audit files | 26 to 30 |
| .....See also audit trail; directories |
| .....auditreduce command | 20 to 22 |
| .....combining | 20 to 22, 26 |
| .....copying login/logout messages tosingle file | 57 to 58 |
| .....directory locations | 27, 31 |
| .....displaying in entirety | 57 |
| .....file token | 50, 83 |
| .....managing size of | 18 |
| .....minimum free space for filesystems | 12 |
| .....names | 27 to 29 |
| ............closed files | 29 |
| ............form | 27 to 28 |
| ............still-active files | 28 to 29 |
| ............time stamps | 28 |
| ............use | 28 |
| .....nonactive files markednot_terminated | 29 to 30, 58 |
| .....order for opening | 12 |
| .....overview | 26 to 27 |
| .....permissions | 32 |
| .....printing | 57 |
| .....reducing | 20 to 22, 26 |
| .....reducing storage-spacerequirements | 23 to 24, 25 |
| .....switching to new file | 17 |
| .....time stamps | 28 |
| audit flags | 8 to 11 |
| .....audit_control file line | 12 |
| .....audit_user file | 13 to 14 |
| .....auditconfig command options | 38 |
| .....C library functions | 157 |
| .....definitions | 9 to 10 |
| .....machine-wide | 8, 12 |
| .....overview | 8 |
| .....policy flags | 39 |
| .....prefixes | 10 to 11 |
| .....process preselection mask | 15 |
| .....syntax | 10 |
| audit ID | 6, 15, 44 |
| audit log files,See audit files |
| audit -n command | 17 |
| audit partitions | 30 to 32 |
| audit policies |
| .....See also audit flags |
| .....auditconfig options | 39 |
| .....setting | 39 |
| audit records | 77 to 147 |
| .....See also audit tokens;specific auditrecords |
| .....audit directories full | 17, 19, 94 |
| .....C library functions | 156 to 157 |
| .....converting to human-readableformat | 8, 20, 45, 59 to 60 |
| .....displaying | 45 |
| .....format or structure | 45 to 55, 78, 95 |
| .....kernel-level generated | 95 to 139 |
| .....overview | 8 |
| .....policy flags | 39 |
| .....reducing audit files | 26 |
| .....selecting | 44 |
| .....self-contained records | 44 |
| .....tools | 44 to 45 |
| .....user-level generated | 139 to 147 |
| audit -s command |
| .....preselection mask for existingprocesses | 12 |
| .....rereading audit files | 17 |
| .....resetting directory pointer | 17 |
| |
| audit server mount-point path names | 31 |
| audit session ID | 15, 44 |
| audit -t command | 16 |
| audit threshold | 12 |
| audit tokens |
| .....arbitrary token | 48 to 49, 79 |
| .....arg token | 49, 81 |
| .....attr token | 49 to 50, 81 |
| .....audit record format | 45 to 55, 78 |
| .....C library functions | 156 |
| .....described | 8 |
| .....exec_args token | 82 |
| .....exec_env token | 82 |
| .....exit token | 50, 82 |
| .....file token | 50, 83 |
| .....groups token | 50 to 51, 84 |
| .....header token | 46, 47 to 48, 84 to 85 |
| .....in_addr token | 51, 85 |
| .....ip token | 51, 85 |
| .....ipc token | 51 to 52, 86 to 87 |
| .....ipc_perm token | 52, 87 |
| .....iport token | 52, 88 |
| .....newgroups token | 88 |
| .....opaque token | 52 to 53, 89 |
| .....order in audit record | 46 |
| .....path token | 53, 89 |
| .....policy flags | 39 |
| .....process token | 53, 90 |
| .....return token | 54, 90 to 91 |
| .....seq token | 54, 91 |
| .....socket token | 54 to 55, 91 to 92 |
| .....socket-inet token | 92 |
| .....subject token | 55, 92 |
| .....table of | 78 |
| .....text token | 55, 93 |
| .....trailer token | 46, 48, 94 |
| .....types | 45 to 46 |
| audit trail |
| .....See also audit files; audit records; audittokens |
| .....analysis | 43 to 60 |
| ............audit record format | 45 to 55 |
| ............auditing features | 43 to 44 |
| ............auditreduce command | 45, 56 to 59 |
| ............costs | 23 |
| ............praudit command | 45, 59 to 60 |
| ............tools | 44 to 45 |
| .....creating | 16 to 18, 26 |
| ............audit daemon's role | 16, 17 |
| ............audit_data file | 16 |
| ............directory suitability | 17 |
| ............managing audit file size | 18 |
| ............overview | 16 |
| .....directory locations | 27, 31 |
| .....events included | 7 |
| .....merging all files | 20 to 22 |
| .....monitoring in real time | 25 |
| .....overflow prevention | 36 to 37 |
| audit_control file |
| .....audit daemon rereading afterediting | 12 |
| .....audit_user file modification | 13 |
| .....C library functions | 156 |
| .....dir: line |
| ............described | 12 |
| ............examples | 13, 32 |
| ............files subdirectory | 31 |
| .....examples | 13, 32 |
| .....flags: line |
| ............described | 12 |
| ............prefixes in | 11 |
| ............process preselection mask | 15 |
| .....minfree: line |
| ............audit_warn condition | 19 |
| ............described | 12 |
| .....naflags: line | 12 |
| .....overview | 11 to 12 |
| .....prefixes inflags line | 11 |
| .....problem with contents | 20 |
| audit_data file | 16 |
| audit_event file |
| .....See also audit events |
| .....audit event type | 45 |
| .....overview | 7 to 8 |
| audit_startup file | 6 |
| audit_user file |
| .....prefixes for flags | 11 |
| .....process preselection mask | 15 |
| .....user audit fields | 13 to 14 |
| |
| audit_warn script | 18 to 20 |
| .....allhard string | 19 |
| .....allsoft string | 19 |
| .....audit daemon execution of | 17 |
| .....auditsvc string | 19 |
| .....conditions invoking | 18 to 20 |
| .....described | 16, 18 |
| .....ebusy string | 19 |
| .....hard string | 19 |
| .....postsigterm string | 19 |
| .....soft string | 18 |
| .....tmpfile string | 19 |
| auditconfig command |
| .....audit flags as arguments | 9 |
| .....options | 37 to 39 |
| .....prefixes for flags | 11 |
| .....reducing storage-spacerequirements | 24 |
| auditd daemon |
| .....audit trail creation | 16, 17 |
| .....audit_startup file | 6 |
| .....audit_warn script |
| ............conditions invoking | 18 to 20 |
| ............described | 16, 18 |
| ............execution of | 17 |
| .....directories suitable to | 17 |
| .....enabling auditing | 6 |
| .....functions | 17 |
| .....order audit files are opened | 12 |
| .....rereading theaudit_controlfile | 12 |
| .....terminating | 16 |
| auditing,See administering auditing;audit trail |
| auditon audit record |
| .....A_GETCAR command | 97 |
| .....A_GETCLASS command | 97 |
| .....A_GETCOND command | 97 |
| .....A_GETCWD command | 97 |
| .....A_GETKMASK command | 98 |
| .....A_GETPOLICY command | 98 |
| .....A_GETQCTRL command | 98 |
| .....A_GETSTAT command | 98 |
| .....A_SETCLASS command | 99 |
| .....A_SETCOND command | 99 |
| .....A_SETKMASK command | 99 |
| .....A_SETPOLICY command | 100 |
| .....A_SETQCRTL command | 101 |
| .....A_SETSMASK command | 99 to 100 |
| .....A_SETSTAT command | 100 |
| .....A_SETUMASK command | 100 |
| auditreduce command | 20 to 22 |
| .....-a option | 58 to 59 |
| .....-b option | 58 to 59 |
| .....capabilities | 56 |
| .....cleaningnot_terminated files | 29 to 30, 58 |
| .....-d option | 57 |
| .....described | 20 to 21, 44, 56 |
| .....distributed systems | 56 |
| .....examples | 57 to 58 |
| .....-m option | 59 |
| .....-O option | 26, 30, 57 to 58 |
| .....options | 20, 58 to 59 |
| .....time stamp use | 28 |
| .....without options | 20 to 22 |
| auditsvc |
| .....audit record | 101 |
| .....system call |
| ............fails | 19, 94 |
| AUE_... names | 7, 8 |
| .....event-to-system call translationtable | 147 to 152 |
| automatically enabling auditing | 6 |
B
| |
| -b option ofauditreduce command | 58 to 59 |
| backslash (\) ending file lines | 65, 67 |
| Basic Security Module (BSM) |
| .....client-server relationships | 2 |
| .....disabling | 2 |
| .....enabling | 2 |
| .....installing | 1 to 3 |
| .....packages | 1 |
| binary audit record format | 45 |
| BSM,See Basic Security Module (BSM) |
| bsmconv script |
| |
| .....devicemaps file creation | 64 |
| .....enabling BSM | 2 |
| bsmunconv script | 2 |
C
| |
| C library functions | 156 to 157 |
| C2 TCSEC features | 61 |
| carat (^) in audit flag prefixes | 11 |
| cartridge tape drives,See tape drives |
| CD-ROM drives |
| .....See also device allocation |
| .....device-clean scripts | 69 |
| change password audit record | 145 |
| chdir audit record | 101 |
| -chkconf option ofauditconfigcommand | 37 |
| chmod audit record | 102 |
| chown audit record | 102 |
| chroot audit record | 102 |
| cl audit flag | 9 |
| classes |
| .....auditconfig command options | 38 |
| .....changing definitions | 40 |
| .....flags and definitions | 9 to 10 |
| .....mapping events | 7, 40 |
| .....overview | 7 to 8 |
| .....selecting for auditing | 7 |
| clean scripts,See device-clean scripts |
| cleaningnot_terminated files | 29 to 30, 58 |
| clients, enabling BSM for | 3 |
| close audit record | 103 |
| cnt policy | 35 to 36 |
| .....flag | 39 |
| combining audit files | 26 |
| .....auditreduce command | 20 to 22 |
| commands |
| .....See alsospecific commands |
| .....device-allocation utilities | 63 to 64 |
| .....maintenance commands | 155 to 156 |
| comments |
| .....device_allocate file | 67 |
| .....device_maps file | 65 |
| -conf option ofauditconfigcommand | 37 |
| configuring |
| .....audit trail overflow prevention | 36 to 37 |
| .....auditconfig command | 37 to 39 |
| .....overview | 32 to 33 |
| .....planning | 33 to 36 |
| .....setting audit policies | 39 |
| converting audit records to human-readable format | 8, 20, 45, 59 to 60 |
| copying login/logout messages to singlefile | 57 to 58 |
| cost control | 22 to 24 |
| .....analysis | 23 |
| .....processing time | 23 |
| .....storage | 23 to 24 |
| creat audit record | 103 |
| creating the audit trail | 16 to 18 |
| .....audit daemon's role | 17 |
| .....audit_data file | 16 |
| .....directory suitability | 17 |
| .....managing audit file size | 18 |
| .....overview | 16 |
| cron job | 18 |
| crontab audit record |
| .....cron-invoke atjob orcrontab | 142 |
| .....crontab-crontab created | 142 |
| .....crontab-crontab deleted | 142 |
| .....crontab-permission | 143 |
D
| |
| -d option |
| .....auditreduce command | 57 |
| .....praudit command | 59 |
| daemon, audit,See audit daemon |
| date-timeauditreduce commandoptions | 58 to 59 |
| deallocate command |
| .....allocate error state | 64 |
| |
| .....described | 63, 75 |
| .....device-clean scripts and | 70 |
| .....using | 76 |
| debugging sequence number | 54, 91 |
| defaults |
| .....audit policies | 39 |
| .....audit_startup file | 6 |
| .....machine-wide | 8 |
| .....praudit output format | 59, 60 |
| ............header token | 48 |
| device allocation | 61 to 76 |
| .....adding devices | 74 |
| .....allocatable devices | 66, 67, 74 |
| .....allocate command |
| ............how the allocate mechanismworks | 71 to 73 |
| ............options | 63 |
| ............using | 75 to 76 |
| .....allocate error state | 64 |
| .....allocating a device | 75 to 76 |
| .....components of the allocationmechanism | 62 |
| .....deallocate command |
| ............allocate error state | 64 |
| ............described | 63, 75 |
| ............device-clean scripts and | 70 |
| ............using | 76 |
| .....device_allocate file | 66 to 68 |
| .....device_maps file | 64 to 66 |
| .....device-clean scripts | 68 to 70 |
| ............adding devices | 74 |
| ............audio devices | 70 |
| ............CD-ROM drives | 69 |
| ............described | 68 |
| ............diskette drives | 69 |
| ............options | 70 |
| ............tape drives | 67, 69 |
| ............writing new scripts | 70 |
| .....list_devices command | 64, 75 |
| .....lock file setup | 70 to 73 |
| .....managing devices | 74 |
| .....reallocating | 63 |
| .....risks associated with device use | 62 |
| .....using device allocations | 75 to 76 |
| .....utilities | 63 to 64 |
| device_allocate file |
| .....format | 67 to 68 |
| .....overview | 66 to 68 |
| device_maps file |
| .....format | 65 to 66 |
| .....overview | 64 |
| device-clean scripts |
| .....adding devices | 74 |
| .....audio devices | 70 |
| .....CD-ROM drives | 69 |
| .....described | 68 |
| .....diskette drives | 69 |
| .....options | 70 |
| .....tape drives | 67, 69 |
| .....writing new scripts | 70 |
| devices |
| .....See also device allocation |
| .....adding | 74 |
| .....lock files | 70 to 73 |
| .....managing | 74 |
| dir: line inaudit_control file |
| .....described | 12 |
| .....example | 13, 32 |
| .....forfiles subdirectory | 31 |
| directories |
| .....audit daemon pointer | 17 |
| .....audit directories full | 17, 19, 94 |
| .....audit directory locations | 27, 31 |
| .....audit partitions | 30 to 32 |
| .....audit_control file definitions | 12 |
| .....diskfull machines | 27, 30 |
| .....files subdirectory | 31 |
| .....mounting audit directories | 27 |
| .....permissions | 32 |
| .....suitable to audit daemon | 17 |
| disabling BSM | 2 |
| diskette drives |
| .....See also device allocation |
| .....device-clean scripts | 69 |
| diskfull machines' audit directory | 27, 30 |
| diskless clients, enabling BSM for | 3 |
| disk-space requirements | 23 to 24 |
| displaying |
| .....audit log in entirety | 57 |
| |
| .....audit records | 45 |
| distributed systems'auditreducecommand use | 56 |
| dminfo command | 64 |
| drives,See device allocation |
E
| |
| ebusy string andaudit_warn script | 19 |
| efficiency | 25 to 26 |
| eject command | 69 |
| enabling |
| .....auditing | 6 |
| .....BSM | 2 |
| ending |
| .....disabling BSM | 2 |
| .....signal received during auditingshutdown | 19 |
| .....terminating audit daemon | 16 |
| enter prom audit record | 103 |
| errors |
| .....allocate error state | 64 |
| .....audit directories full | 17, 19, 94 |
| .....internal errors | 19 |
| /etc/security directory | 31 |
| /etc/security/audit directory | 27, 31 |
| /etc/security/audit/bsmconv script |
| .....enabling BSM | 2 |
| .....devicemaps file creation | 64 |
| /etc/security/audit/bsmunconvscript | 2 |
| /etc/security/audit_control file,Seeaudit_control file |
| /etc/security/audit_data file | 16 |
| /etc/security/audit_event file |
| .....audit event type | 45 |
| .....overview | 7 to 8 |
| .....See also audit events |
| /etc/security/audit_startupfile | 6 |
| /etc/security/audit_warnscript | 16, 18 to 20 |
| /etc/security/dev lock files | 70 to 73 |
| event modifier field flags (headertoken) | 85 |
| event numbers | 8 |
| events |
| .....See also audit classes |
| .....C library functions | 156 |
| .....categories | 8 |
| .....event-to-system call translationtable | 147 to 152 |
| .....including in audit trail | 7 |
| .....kernel events |
| ............audit tokens | 46 |
| ............auditconfig commandoptions | 37, 38 |
| ............described | 7 |
| .....mapping to classes | 7, 40 |
| .....numbers | 8 |
| .....overview | 7 to 8 |
| .....preselecting | 156 |
| .....record formats and | 45 |
| .....user-level events |
| ............audit tokens | 46 |
| ............auditconfig commandoptions | 38 |
| ............described | 8 |
| ex audit flag | 10 |
| exec audit class | 10 |
| exec audit record | 104 |
| exec_args token | 82 |
| exec_env token | 82 |
| execve audit record | 104 |
| exit audit record | 105 |
| exit prom audit record | 104 |
| exit token | 50, 82 |
| export list | 27 |
F
| |
| -F option |
| .....allocate command | 63 |
| .....deallocate command | 63 |
| .....st_clean script | 70 |
| fa audit flag | 9 |
| failure |
| |
| .....audit flag prefix | 10 |
| .....turning off audit flags for | 11 |
| fc audit flag | 9 |
| fchdir audit record | 105 |
| fchmod audit record | 105 |
| fchown audit record | 106 |
| fchroot audit record | 106 |
| fcntl audit record | 106 |
| fd audit flag | 9 |
| fd_clean script | 69 |
| file systems,See audit files; directories |
| file token | 50, 83 |
| file vnode token | 49 to 50, 81 |
| file_attr_acc audit class | 9 |
| file_attr_mod audit class | 9 |
| file_close audit class | 9 |
| file_creation audit class | 9 |
| file_deletion audit class | 9 |
| file_read audit class | 9 |
| file_write audit class | 9 |
| files subdirectory | 31 |
| files, audit,See audit files |
| files, lock | 70 to 73 |
| flags | 8 to 11 |
| .....audit_control file line | 12 |
| .....audit_user file | 13 to 14 |
| .....auditconfig command options | 38 |
| .....C library functions | 157 |
| .....definitions | 9 to 10 |
| .....machine-wide | 8, 12 |
| .....overview | 8 |
| .....policy flags | 39 |
| .....prefixes | 10 to 11 |
| .....process preselection mask | 15 |
| .....syntax | 10 |
| flags: line inaudit_control file |
| .....described | 12 |
| .....prefixes in | 11 |
| .....process preselection mask | 15 |
| fm audit flag | 9 |
| forced cleanup | 70 |
| fork audit record | 107 |
| fork1 audit record | 107 |
| fr audit flag | 9 |
| fstatfs audit record | 108 |
| ftpd login audit record | 143 |
| fw audit flag | 9 |
G
| |
| getaudit audit record | 108 |
| getauid audit record | 108 |
| -getclass option ofauditconfigcommand | 38 |
| -getcond option ofauditconfigcommand | 38 |
| getmsg audit record | 109 |
| .....socket accept | 109 |
| .....socket receive | 109 |
| -getpinfo option ofauditconfigcommand | 38 |
| getpmsg audit record | 110 |
| -getpolicy option ofauditconfigcommand | 39 |
| getportaudit audit record | 110 |
| graphics tablets,See device allocation |
| group policy |
| .....flag | 39 |
| .....groups token | 50 to 51, 84 |
| .....newgroups token | 88 |
| groups token | 50 to 51, 84 |
H
| |
| halt: machine halt audit record | 143 |
| hard string withaudit_warn script | 19 |
| hard-disk-space requirements | 23 to 24 |
| header token |
| .....described | 47, 84 to 85 |
| .....event-modifier field flags | 85 |
| .....fields | 47 |
| .....format | 85 |
| .....order in audit record | 46, 84 |
| .....praudit display | 48 |
| headers | 157 |
| |
| human-readable audit record format |
| .....See also audit tokens |
| .....converting audit records to | 8, 20, 45, 59 to 60 |
| .....described | 45 to 55 |
I
| |
| -I option |
| .....deallocate command | 64 |
| .....st_clean script | 70 |
| IDs |
| .....audit | 6, 15, 44 |
| .....audit session | 15, 44 |
| .....audit user | 44 |
| .....auditconfig command options | 38 |
| .....terminal | 15 |
| in.ftpd audit record | 143 |
| in.rexecd audit record | 146 |
| in.rshd: rshd accessdenials/grants auditrecord | 146 to 147 |
| in_addr token | 51, 85 |
| inetd: inetd service request auditrecord | 143 |
| installing BSM | 1 to 3 |
| Internet-related tokens |
| .....in_addr token | 51, 85 |
| .....ip token | 51, 85 |
| .....iport token | 52, 88 |
| .....socket token | 54 to 55, 91 to 92 |
| .....socket-inet token | 92 |
| io audit flag | 9 |
| ioctl audit class | 9 |
| ioctl system calls | 9, 70 |
| ioctl: ioctl to special devicesaudit record | 110 to 111 |
| ip audit flag | 9 |
| ip token | 51, 85 |
| ipc audit class | 9 |
| ipc token | 51 to 52, 86 to 87 |
| ipc type field values (ipc token) | 87 |
| ipc_perm token | 52, 87 |
| iport token | 52, 88 |
| item size field values (arbitrarytoken) | 80 |
K
| |
| kernel events |
| .....See also audit events |
| .....audit records | 95 to 139 |
| .....audit tokens | 46 |
| .....auditconfig command options | 37, 38 |
| .....described | 7 |
| kill audit record | 111 |
L
| |
| -l option |
| .....praudit command | 59 |
| lchown audit record | 111 to 112 |
| libraries, C functions | 156 to 157 |
| link audit record | 112 |
| list_devices command | 64, 75 |
| lo audit flag | 9 |
| lock files |
| .....how the allocate mechanismworks | 71 to 73 |
| .....setting up | 71 |
| log files,See audit files |
| login audit record |
| .....logout | 144 |
| .....rlogin | 144 |
| .....telnet login | 144 |
| .....terminal login | 144 |
| login/logout messages, copying to singlefile | 57 to 58 |
| login_logout audit class | 9 |
| -lsevent option ofauditconfigcommand | 38 |
| -lspolicy option ofauditconfigcommand | 39 |
| lstat audit record | 112 |
| lxstat audit record | 112 |
M
| |
| -m option ofauditreduce command | 59 |
| machine halt audit record | 143 |
| machine reboot audit record | 145 |
| macros | 157 |
| maintenance commands | 155 to 156 |
| managing devices | 74 |
| mappings, class | 7, 40 |
| mask, process preselection |
| .....auditconfig command options | 38 |
| .....C library functions | 156 |
| .....described | 15 |
| .....machine-wide | 12 |
| .....reducing storage costs | 23 to 24 |
| memcntl audit record | 113 |
| minfree: line inaudit_control file |
| .....audit_warn condition | 18, 19 |
| .....described | 12 |
| .....determining space needed | 34 |
| minus (-) audit flag prefix | 10 to 11 |
| mkdir audit record | 113 |
| mknod audit record | 113 |
| mmap audit record | 114 |
| modctl audit record |
| .....MODADDMAJBIND command | 114 |
| .....MODCONFIG command | 115 |
| .....MODLOAD command | 115 |
| .....MODUNLOAD command | 115 |
| modems,See device allocation |
| monitoring audit trail in real time | 25 |
| mount audit record | 116 |
| mountd audit record |
| .....NFS mount request | 145 |
| .....NFS unmount request | 145 |
| mounting audit directories | 27 |
| msgctl audit record |
| .....IPC_RMID command | 116 |
| .....IPC_SET command | 116 to 117 |
| .....IPC_STAT command | 117 |
| msgget audit record | 117 |
| msgrcv audit record | 117 |
| msgsnd audit record | 118 |
| mt command, device-cleanup option | 69 |
| munmap audit record | 118 |
N
| |
| na audit flag | 9 |
| naflags: line inaudit_controlfile | 12 |
| names |
| .....audit classes | 9 to 10 |
| .....audit files |
| ............closed files | 29 |
| ............form | 27 to 28 |
| ............still-active files | 28 to 29 |
| ............time stamps | 28 |
| ............use | 28 |
| .....audit flags | 9 to 10 |
| .....device names |
| ............device_allocate file | 67 |
| ............device_maps file | 65 |
| .....IDs |
| ............audit | 6, 15 |
| ............audit session | 15, 44 |
| ............auditconfig commandoptions | 38 |
| ............terminal | 15 |
| .....kernel events | 7 |
| .....mount-point path names on auditservers | 31 |
| .....user-level events | 8 |
| network audit class | 9 |
| never-audit flags | 13 to 14 |
| newgroups token | 88 |
| NFS mount request audit record | 145 |
| NFS unmount request auditrecord | 145 |
| nice audit record | 118 |
| no audit flag | 9 |
| no_class audit class | 9 |
| non_attrib audit class | 9 |
| nonattributable flags inaudit_controlfile | 12 |
| normal users, auditing | 25 |
| |
| not_terminated files, cleaning | 29 to 30, 58 |
| nt audit flag | 9 |
| null audit class | 9 |
| numbers, event | 8 |
O
| |
| -O option ofauditreduce command | 26, 30, 57 to 58 |
| object-reuse requirement | 61, 68 to 70 |
| .....device-clean scripts |
| ............adding devices | 74 |
| ............audio devices | 70 |
| ............CD-ROM drives | 69 |
| ............described | 68 |
| ............diskette drives | 69 |
| ............tape drives | 67, 69 |
| ............writing new scripts | 70 |
| opaque token | 52 to 53, 89 |
| open audit record |
| .....read | 119 |
| .....read, create | 119 |
| .....read, create, truncate | 119 |
| .....read, truncate | 120 |
| .....read, write | 120 |
| .....read, write, create | 120 |
| .....read, write, create,truncate | 120 |
| .....read, write, truncate | 121 |
| .....write | 121 |
| .....write, create | 121 |
| .....write, create, truncate | 122 |
| .....write, truncate | 122 |
| ot audit flag | 10 |
| other audit class | 10 |
| overflow prevention for audit trail | 36 to 37 |
P
| |
| partitions, audit | 30 to 32 |
| passwd audit record | 145 |
| path policy flag | 39 |
| path token | 53, 89 |
| pathconf audit record | 122 |
| pc audit flag | 9 |
| permissions for audit file systems | 32 |
| pipe audit record | 122 to 123 |
| plus (+) audit flag prefix | 10 to 11 |
| policies |
| .....See also audit flags |
| .....auditconfig options | 39 |
| .....setting | 39 |
| postsigterm string andaudit_warnscript | 19 |
| pound sign (#) for comments in files | 65, 67 |
| praudit command |
| .....See also audit tokens |
| .....converting audit records to human-readable format | 8, 20 |
| .....described | 45 |
| .....human-readable format | 46 to 55 |
| .....output formats | 59 to 60 |
| .....pipingauditreduce output to | 57 |
| .....using | 59 to 60 |
| prefixes in audit flags | 10 to 11 |
| preselection mask |
| .....auditconfig command options | 38 |
| .....C library functions | 156 |
| .....described | 15 |
| .....machine-wide | 12 |
| .....reducing storage costs | 23 to 24 |
| primary audit directory | 12, 30 |
| print format field values (arbitrarytoken) | 80 |
| printing audit log | 57 |
| priocnt audit record | 123 |
| process audit characteristics | 14 to 15 |
| .....audit ID | 15 |
| .....audit session ID | 15 |
| .....process preselection mask | 15, 23 to 24 |
| .....terminal ID | 15 |
| process audit class | 9 |
| |
| process dumped core auditrecord | 123 |
| process groups tokens |
| .....groups token | 50 to 51, 84 |
| .....newgroups token | 88 |
| process preselection mask |
| .....auditconfig command options | 38 |
| .....described | 15 |
| .....reducing storage costs | 23 to 24 |
| process token | 53, 90 |
| processing time costs | 23 |
| putmsg audit record | 123 |
| .....socket connect | 124 |
| .....socket send | 124 |
| putpmsg audit record | 124 |
R
| |
| -r praudit output format | 59, 60 |
| .....header token | 48 |
| rawpraudit output format | 59, 60 |
| .....header token | 48 |
| readlink audit record | 124 |
| reallocating devices | 63 |
| reboot: machine reboot auditrecord | 145 |
| records,See audit records |
| reducing audit files | 26 |
| .....auditreduce command | 20 to 22 |
| .....storage-space requirements | 23 to 24, 25 |
| rename audit record | 125 |
| return token | 54, 90 to 91 |
| rewoffl option ofmt command | 69 |
| risks associated with device use | 62 |
| rmdir audit record | 125 |
| rpc.rexd audit record | 146 |
| rshd access denials/grants auditrecord | 146 to 147 |
S
| |
| -S option ofst_clean script | 70 |
| -s praudit output format | 59 |
| .....header token | 48 |
| SCSI devices |
| .....See also device allocation |
| .....st_clean script | 67 |
| secondary audit directory | 12, 30 |
| security risks associated with deviceuse | 62 |
| selecting audit records | 44 |
| semctl audit record |
| .....GETALL command | 125 |
| .....GETNCNT command | 126 |
| .....GETPID command | 126 |
| .....GETVAL command | 126 |
| .....GETZCNT command | 127 |
| .....IPC_RMID command | 127 |
| .....IPC_SET command | 127 |
| .....IPC_STAT command | 128 to 129 |
| .....SETALL command | 128 |
| .....SETVAL command | 128 |
| semget audit record | 129 |
| semop audit record | 129 |
| seq policy flag | 40 |
| seq token | 54, 91 |
| servers, enabling BSM for clients | 3 |
| session ID | 15, 44 |
| setaudit audit record | 129 to 130 |
| setauid audit record | 130 |
| -setclass option ofauditconfigcommand | 38 |
| -setcond option ofauditconfigcommand | 38 |
| setegid audit record | 130 |
| seteuid audit record | 130 |
| setgid audit record | 131 |
| setgroups audit record | 131 |
| setpgrp audit record | 131 |
| -setpmask option ofauditconfigcommand | 38 |
| -setpolicy option ofauditconfigcommand | 39 |
| setrlimit audit record | 132 |
| |
| -setsmask option ofauditconfigcommand | 38 |
| setuid audit record | 132 |
| -setumask option ofauditconfigcommand | 38 |
| SHIELD Basic Security Module,See BasicSecurity Module (BSM) |
| shmat audit record | 132 |
| shmctl audit record |
| .....IPC_RMID command | 133 |
| .....IPC_SET command | 133 |
| .....IPC_STAT command | 133 to 134 |
| shmdt audit record | 134 |
| shmget audit record | 134 |
| shortpraudit output format | 59 |
| .....header token | 48 |
| shutting down,See terminating |
| signal received during auditingshutdown | 19 |
| size |
| .....managing audit files | 18 |
| .....reducing audit files | 26 |
| ............auditreduce command | 20 to 22 |
| ............storage-space requirements | 23 to 24, 25 |
| socket accept audit record | 109 |
| socket connect audit record | 124 |
| socket receive audit record | 109 |
| socket send audit record | 124 |
| socket token | 54 to 55, 91 to 92 |
| socket-inet token | 92 |
| soft limit |
| .....audit_warn condition | 18 |
| .....determining space needed | 34 |
| .....minfree: line described | 12 |
| soft string withaudit_warn script | 18 |
| Solaris SHIELD Basic Security Module,SeeBasic Security Module (BSM) |
| sr_clean script | 69 |
| st_clean script for tape drives | 67, 69 |
| standard cleanup | 70 |
| starting,See enabling |
| stat audit record | 134 |
| statfs audit record | 135 |
| statvfs audit record | 135 |
| stime audit record | 135 |
| storage costs | 23 to 24 |
| storage overflow prevention | 36 to 37 |
| su audit record | 147 |
| subject token | 55, 92 |
| success |
| .....audit flag prefix | 10 |
| .....turning off audit flags for | 11 |
| SUNWcar package | 1 |
| SUNWcsr package | 1 |
| SUNWcsu package | 1 |
| SUNWhea package | 1 |
| SUNWman package | 1 |
| symlink audit record | 136 |
| sysinfo audit record | 136 |
| system booted audit record | 136 |
| system calls |
| .....arg token | 49, 81 |
| .....auditsvc fails | 19, 94 |
| .....close | 9 |
| .....event numbers | 7 |
| .....event-to-system call translationtable | 147 to 152 |
| .....exec_args token | 82 |
| .....exec_env token | 82 |
| .....ioctl | 9, 70 |
| .....return token | 54, 90 to 91 |
| .....table | 156 |
| System V IPC |
| .....ipc audit class | 9 |
| .....ipc token | 51 to 52, 86 to 87 |
| .....ipc_perm token | 52, 87 |
T
| |
| tables | 157 |
| tail command | 25 |
| tape drives |
| .....See also device allocation |
| |
| .....device-clean scripts | 69 |
| .....risks associated with use | 62 |
| .....st_clean script | 67 |
| TCP address | 52, 88 |
| TCSEC (Trusted Computer SystemEvaluation Criteria) C2features | 61 |
| temporary file cannot be used | 19 |
| terminal ID | 15 |
| terminals,See device allocation |
| terminating |
| .....audit daemon | 16 |
| .....signal received during auditingshutdown | 19 |
| text token | 55, 93 |
| time stamps in audit files | 28 |
| time-dateauditreduce commandoptions | 58 to 59 |
| tmpfile string andaudit_warnscript | 19 |
| tokens,See audit tokens |
| trail policy flag | 40 |
| trail,See audit trail |
| trailer token |
| .....described | 48, 94 |
| .....fields | 48 |
| .....format | 94 |
| .....order in audit record | 46, 94 |
| .....praudit display | 48 |
| Trusted Computer System EvaluationCriteria (TCSEC) C2 features | 61 |
U
| |
| -U option |
| .....allocate command | 63 |
| .....list_devices command | 64 |
| UDP address | 52, 88 |
| umount: old version auditrecord | 136 |
| unlink audit record | 137 |
| user audit fields | 13 to 14 |
| user ID (audit ID) | 6, 15, 44 |
| user-level events |
| .....See also audit events |
| .....audit records | 139 to 147 |
| .....audit tokens | 46 |
| .....auditconfig command options | 38 |
| .....described | 8 |
| /usr/bin/at audit record |
| .....at-create crontab | 141 |
| .....at-delete atjob | 141 |
| .....at-permission | 141 |
| /usr/bin/crontab audit record |
| .....cron-invoke atjob orcrontab | 142 |
| .....crontab-crontab created | 142 |
| .....crontab-crontab deleted | 142 |
| .....crontab-permission | 143 |
| /usr/bin/login audit record |
| .....logout | 144 |
| .....rlogin | 144 |
| .....telnet login | 144 |
| .....terminal login | 144 |
| /usr/bin/passwd: change passwordaudit record | 145 |
| /usr/bin/su audit record | 147 |
| /usr/lib/nfs/mountd audit record |
| .....NFS mount request | 145 |
| .....NFS unmount request | 145 |
| /usr/sbin/allocate audit record |
| .....allocate-list devicesuccess | 140 |
| .....deallocate device | 140 |
| .....deallocate device failure | 140 |
| .....device allocate failure | 140 |
| .....device allocate success | 139 |
| /usr/sbin/auditd daemon,See auditdaemon |
| /usr/sbin/halt audit record | 143 |
| /usr/sbin/in.ftpd audit record | 143 |
| /usr/sbin/in.rexecd auditrecord | 146 |
| /usr/sbin/in.rshd audit record | 146 to 147 |
| /usr/sbin/inetd audit record | 143 |
| /usr/sbin/reboot audit record | 145 |
| |
| /usr/sbin/rpc.rexd audit record | 146 |
| utilities |
| .....C library functions | 156 to 157 |
| .....device allocation | 63 to 64 |
| .....headers, tables, and macros | 157 |
| .....maintenance commands | 155 to 156 |
| .....system calls | 156 |
| utime audit record | 137 |
| utimes audit record | 137 |
| utssys - fusers audit record | 138 |
V
| |
| vfork audit record | 138 |
| viewing,See displaying |
| vnode token | 49 to 50, 81 |
| vtrace audit record | 138 |
W
| |
| writing new device-clean scripts | 70 |
X
| |
| xmknod audit record | 138 |
| xstat audit record | 139 |
| Xylogics tape drive clean script | 67 |
Z
|
|