Managing Auditing in Oracle® Solaris 11.2

Exit Print View

Updated: July 2014
 
 

Enabling and Disabling the Audit Service

The audit service is enabled by default. If the perzone audit policy is set, zone administrators must enable, refresh, or disable the audit service in each non-global zone as desired. If the perzone audit policy is not set, enabling, refreshing, or disabling the audit service from the global zone is effective for all non-global zones.

To disable or enable the audit service, you must become an administrator who is assigned the Audit Control rights profile. For more information, see Using Your Assigned Administrative Rights in Securing Users and Processes in Oracle Solaris 11.2 .

To disable the audit service, use the following command:

# audit -t

To enable the audit service, use the following command:

# audit -s

To verify that the audit service is running, use the following command:

# auditconfig -getcond
audit condition = auditing

If the perzone audit policy is set, then you must perform this verification in the non-global zones where you enabled auditing.

For more information, see the audit (1M) and auditd (1M) man pages.