Managing Auditing in Oracle® Solaris 11.2

Exit Print View

Updated: July 2014
 
 

file Token

The file token is a special token that marks the beginning of a new audit file and the end of an old audit file as the old file is deactivated. The initial file token identifies the previous file in the audit trail. The final file token identifies the next file in the audit trail. These tokens link successive audit files into one audit trail.

The praudit -x command shows the fields of the file token. The line in the following example is wrapped for display purposes.

<file iso8601="2009-04-08 14:18:26.200 -07:00">
/var/audit/machine1/files/20090408211826.not_terminated.machine1</file>