Trusted Solaris Audit Administration
    
A
 
 aa audit class ( Index Term Link ) ( Index Term Link )
 
 aa audit flag ( Index Term Link )
 
 access audit record ( Index Term Link )
 
 acct audit record ( Index Term Link )
 
 acl token ( Index Term Link )
 
 ad audit flag ( Index Term Link )
 
 add_drv audit record ( Index Term Link )
 
 adjtime audit record ( Index Term Link )
 
 Admin Editor audit record ( Index Term Link )
 
 administrative roles, assuming ( Index Term Link )
 
 ahlt policy, flag ( Index Term Link )
 
 aliases, creating audit_warn mail alias ( Index Term Link )
 
 all
  audit flag ( Index Term Link )
   caution for using ( Index Term Link )
  in user audit fields ( Index Term Link )
 
 allhard string with audit_warn script ( Index Term Link ) ( Index Term Link )
 
 allocate audit record
  deallocate device ( Index Term Link )
  deallocate device failure ( Index Term Link )
  device allocate failure ( Index Term Link )
  device allocate success ( Index Term Link )
  list device failure ( Index Term Link )
  list device success ( Index Term Link )
 
 allsoft string with audit_warn script ( Index Term Link )
 
 always-audit flags
  described ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 ao audit class ( Index Term Link ) ( Index Term Link )
 
 ao audit flag ( Index Term Link )
 
 ap audit class ( Index Term Link )
 
 ap audit flag ( Index Term Link )
 
 arbitrary token ( Index Term Link )
 
 arg token ( Index Term Link )
 
 arge policy, exec_env token and ( Index Term Link )
 
 argv policy, exec_args token and ( Index Term Link )
 
 as audit class ( Index Term Link )
 
 as audit flag ( Index Term Link )
 
 at audit record
  at-create crontab ( Index Term Link )
  at-delete atjob ( Index Term Link )
  at-permission ( Index Term Link )
 
 attr token ( Index Term Link )
 
 audit -n command ( Index Term Link )
 
 audit -s command
  preselection mask for existing processes ( Index Term Link )
  rereading audit files ( Index Term Link ) ( Index Term Link )
  resetting directory pointer ( Index Term Link )
 
 audit -t command ( Index Term Link )
 
 audit attributes
  See audit tokens
 
 audit audit record ( Index Term Link ) ( Index Term Link )
 
 audit classes
  adding ( Index Term Link )
  changing definitions ( Index Term Link )
  mapping events ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  selecting for auditing ( Index Term Link )
  setting mappings for attributable events ( Index Term Link )
  setting mappings for non-attributable events ( Index Term Link )
 
 audit clients ( Index Term Link )
 
 audit_control file
  audit daemon rereading after editing ( Index Term Link )
  audit_user file modification ( Index Term Link )
  dir: line
   examples ( Index Term Link )
   files ( Index Term Link ) ( Index Term Link )
  dir: line described ( Index Term Link )
  examples ( Index Term Link )
  flags: line
   described ( Index Term Link )
   prefixes in ( Index Term Link )
   process preselection mask ( Index Term Link )
  minfree: line
   audit_warn condition ( Index Term Link )
   described ( Index Term Link )
  naflags: line ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  prefixes in flags line ( Index Term Link )
  problem with contents ( Index Term Link )
 
 audit daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  directories suitable to ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
  starting ( Index Term Link )
  starting manually ( Index Term Link )
 
 audit_data file ( Index Term Link )
 
 audit directories
  creating ( Index Term Link )
  mounting ( Index Term Link )
 
 audit_event file
  overview ( Index Term Link ) ( Index Term Link )
 
 audit events
  audit_event file
   audit event type ( Index Term Link )
  audited by default ( Index Term Link )
  categories ( Index Term Link )
  finding in audit trail ( Index Term Link )
  including in audit trail ( Index Term Link )
  kernel events
   audit tokens ( Index Term Link )
   auditconfig command options ( Index Term Link )
   described ( Index Term Link )
  mapping to classes ( Index Term Link )
  non-attributable ( Index Term Link )
  numbers ( Index Term Link )
  numbers of system calls ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  pseudo-events ( Index Term Link )
  record formats and ( Index Term Link )
  user-level events
   audit tokens ( Index Term Link )
   auditconfig command options ( Index Term Link )
   described ( Index Term Link )
 
 audit files
  /etc/security/audit_class file ( Index Term Link )
  /etc/security/audit_control file ( Index Term Link )
  /etc/security/audit_event file ( Index Term Link )
  /etc/security/audit_user file ( Index Term Link )
  /etc/security/audit_warn file ( Index Term Link )
  backup ( Index Term Link )
  cleaning up not_terminated file ( Index Term Link )
  combing selected ones ( Index Term Link )
  copying login/logout messages to single file ( Index Term Link ) ( Index Term Link )
  directory locations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  displaying in entirety ( Index Term Link )
  managing ( Index Term Link )
  managing size of ( Index Term Link )
  merging ( Index Term Link )
  minimum free space for file systems ( Index Term Link )
  names
   closed files ( Index Term Link )
   examples ( Index Term Link )
   form ( Index Term Link ) ( Index Term Link )
   still-active files ( Index Term Link ) ( Index Term Link )
   time stamps ( Index Term Link )
   use ( Index Term Link )
  nonactive files marked not_terminated ( Index Term Link )
  order for opening ( Index Term Link )
  overflow prevention ( Index Term Link )
  printing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  reading closed file ( Index Term Link )
  reading still-open file ( Index Term Link )
  reducing size ( Index Term Link )
  reducing storage space requirements ( Index Term Link ) ( Index Term Link )
  restoring ( Index Term Link )
  specifying location ( Index Term Link )
  switching to new file ( Index Term Link )
  time stamps ( Index Term Link )
 
 audit flags
  audit_control file line ( Index Term Link )
  audit_user file ( Index Term Link ) ( Index Term Link )
  changing dynamically ( Index Term Link )
  definitions ( Index Term Link )
  list of ( Index Term Link ) ( Index Term Link )
  machine-wide ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  policy flags ( Index Term Link )
  prefixes ( Index Term Link )
  process preselection mask ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 audit IDs
  acquired at login ( Index Term Link )
  ensuring successful tracking ( Index Term Link )
  example audit record ( Index Term Link )
 
 audit log files
  See audit files
 
 audit mappings ( Index Term Link )
 
 audit partitions
  creating ( Index Term Link )
  removing free space ( Index Term Link )
 
 audit policies
  determining ( Index Term Link )
  setting ( Index Term Link ) ( Index Term Link )
  setting temporarily ( Index Term Link )
 
 audit records ( Index Term Link ) ( Index Term Link )
  adding sequence token ( Index Term Link )
  audit directories full ( Index Term Link ) ( Index Term Link )
  audit ID ( Index Term Link )
  audit session ID ( Index Term Link )
  converting to human-readable format ( Index Term Link ) ( Index Term Link )
  displaying by designated dates ( Index Term Link )
  displaying user activities ( Index Term Link )
  features in audit trail ( Index Term Link ) ( Index Term Link )
  format ( Index Term Link )
  format in audit trail ( Index Term Link ) ( Index Term Link )
  format or structure ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  human-readable format ( Index Term Link )
  kernel-level generated ( Index Term Link ) ( Index Term Link )
  login record ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  policy flags ( Index Term Link )
  printing user activities ( Index Term Link )
  pseudo-events ( Index Term Link )
  reading ( Index Term Link )
  removing sequence token ( Index Term Link )
  selecting from audit trail ( Index Term Link )
  self-contained records ( Index Term Link )
  sending to a different file ( Index Term Link )
  time-stamp format ( Index Term Link )
  use of privilege ( Index Term Link )
  user-level generated ( Index Term Link ) ( Index Term Link )
 
 audit script ( Index Term Link ) ( Index Term Link )
 
 audit servers
  mount-point path names ( Index Term Link )
  partitioning example ( Index Term Link )
  planning ( Index Term Link )
 
 audit session ID ( Index Term Link ) ( Index Term Link )
 
 audit_startup file ( Index Term Link )
 
 audit tokens
  acl token ( Index Term Link )
  arbitrary token ( Index Term Link )
  arg token ( Index Term Link )
  attr token ( Index Term Link )
  audit record format ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  examples ( Index Term Link ) ( Index Term Link )
  clearance token ( Index Term Link )
  exec_args token ( Index Term Link )
  exec_env token ( Index Term Link )
  exit token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  file token ( Index Term Link )
  groups token ( Index Term Link )
  header token ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  host token ( Index Term Link )
  in_addr token ( Index Term Link )
  ip token ( Index Term Link )
  ipc_perm token ( Index Term Link )
  ipc token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  iport token ( Index Term Link )
  liaison token ( Index Term Link )
  newgroups token ( Index Term Link )
  opaque token ( Index Term Link )
  order ( Index Term Link )
  order in audit record ( Index Term Link )
  path token ( Index Term Link )
  policy flags ( Index Term Link )
  priv token ( Index Term Link )
  privilege token ( Index Term Link )
  process token ( Index Term Link )
  reading ( Index Term Link )
  return token ( Index Term Link ) ( Index Term Link )
  seq token ( Index Term Link )
  slabel token ( Index Term Link )
  socket-inet token ( Index Term Link )
  socket token ( Index Term Link ) ( Index Term Link )
  subject token ( Index Term Link )
  table of ( Index Term Link )
  text token ( Index Term Link )
  trailer token ( Index Term Link ) ( Index Term Link )
  types ( Index Term Link ) ( Index Term Link )
  xatom token ( Index Term Link )
  xclient token ( Index Term Link )
  xcolormap token ( Index Term Link )
  xcursor token ( Index Term Link )
  xfont token ( Index Term Link )
  xgc token ( Index Term Link )
  xpixmap token ( Index Term Link )
  xproperty token ( Index Term Link )
  xselect token ( Index Term Link )
  xwindow token ( Index Term Link )
 
 audit trail
  analysis
   auditing features ( Index Term Link ) ( Index Term Link )
   auditreduce command ( Index Term Link ) ( Index Term Link )
   costs ( Index Term Link )
   finding failed login attempts ( Index Term Link )
   of cost ( Index Term Link )
   praudit command ( Index Term Link ) ( Index Term Link )
  analyzing ( Index Term Link )
  auditreduce command ( Index Term Link ) ( Index Term Link )
  creating
   audit daemon's role ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit_data file ( Index Term Link )
   directory suitability ( Index Term Link )
   managing audit file size ( Index Term Link )
   overview ( Index Term Link )
  debugging ( Index Term Link )
  directory locations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  events included ( Index Term Link )
  merging ( Index Term Link )
  monitoring in real time ( Index Term Link )
  overflow prevention ( Index Term Link ) ( Index Term Link )
  praudit command ( Index Term Link ) ( Index Term Link )
 
 audit_user file
  prefixes for flags ( Index Term Link )
  process preselection mask ( Index Term Link )
  user audit fields ( Index Term Link ) ( Index Term Link )
 
 audit_warn script ( Index Term Link ) ( Index Term Link )
  allhard string ( Index Term Link ) ( Index Term Link )
  allsoft string ( Index Term Link )
  auditsvc string ( Index Term Link )
  conditions invoking ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ebusy string ( Index Term Link )
  hard string ( Index Term Link )
  postsigterm signal ( Index Term Link )
  soft string ( Index Term Link )
  tmpfile string ( Index Term Link )
 
 auditconfig command
  audit flags as arguments ( Index Term Link )
  changing class mappings ( Index Term Link )
  options ( Index Term Link ) ( Index Term Link )
  prefixes for flags ( Index Term Link )
 
 auditd daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link ) ( Index Term Link )
  directories suitable to ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
 
 auditing
  advanced setup procedures ( Index Term Link ) ( Index Term Link )
  advanced tasks for security administrator ( Index Term Link )
  audit ID ( Index Term Link )
  audit session ID ( Index Term Link )
  for efficiency ( Index Term Link )
  basic setup procedures ( Index Term Link ) ( Index Term Link )
  basic tasks for security administrator ( Index Term Link )
  client-server relationships ( Index Term Link ) ( Index Term Link )
  considerations ( Index Term Link )
  defaults ( Index Term Link ) ( Index Term Link )
   audit_startup file ( Index Term Link )
  disabling ( Index Term Link ) ( Index Term Link )
  dynamic procedures ( Index Term Link )
  enabling ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  overview of administration ( Index Term Link ) ( Index Term Link )
  planning ( Index Term Link ) ( Index Term Link )
  removing free space ( Index Term Link )
  setup tasks for system administrator ( Index Term Link )
  shutdown ( Index Term Link )
  site planning ( Index Term Link )
  software packages ( Index Term Link )
  space planning ( Index Term Link ) ( Index Term Link )
  startup ( Index Term Link ) ( Index Term Link )
  user ID ( Index Term Link )
  warning of trouble ( Index Term Link )
 
 auditon audit record
  A_GETCAR command ( Index Term Link )
  A_GETCLASS command ( Index Term Link )
  A_GETCOND command ( Index Term Link )
  A_GETCWD command ( Index Term Link )
  A_GETKMASK command ( Index Term Link )
  A_GETSTAT command ( Index Term Link )
  A_GPOLICY command ( Index Term Link )
  A_GQCTRL command ( Index Term Link )
  A_SETCLASS command ( Index Term Link )
  A_SETCOND command ( Index Term Link )
  A_SETKMASK command ( Index Term Link )
  A_SETSMASK command ( Index Term Link )
  A_SETSTAT command ( Index Term Link )
  A_SETUMASK command ( Index Term Link )
  A_SPOLICY command ( Index Term Link )
  A_SQCTRL command ( Index Term Link )
 
 auditpsa audit record ( Index Term Link )
 
 auditreduce command
  capabilities ( Index Term Link )
  cleaning not_terminated files ( Index Term Link )
  described ( Index Term Link )
  distributed systems ( Index Term Link )
  examples ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  time stamp use ( Index Term Link )
 
 auditstat audit record ( Index Term Link )
 
 auditsvc, system call fails ( Index Term Link )
 
 auditsvc audit record ( Index Term Link )
 
 auditwrite audit record ( Index Term Link )
 
 AUE_... names ( Index Term Link )
 
 authorization use audit record ( Index Term Link )
 
 ax audit class ( Index Term Link )
 
 ax audit flag ( Index Term Link )