Trusted Solaris Audit Administration

Security Administrator's Audit Setup Tasks - Basic

Table 2-2 Basic Auditing Setup by the Security Administrator

Task 

For the procedure, see...  

On first workstation 

 

Edit audit_control file 

"To Set Audit Flags"

 

 

 

"To Reserve Free Space on an Audit File System"

"To Specify the Audit File Storage Locations"

Set Solaris security attributes 

"To Protect an Audit File System"

Edit audit_user file  

"To Set User Exceptions to the Audit Flags"

Edit audit_startup file 

"To Set Audit Policy Permanently"

Copy for distribution 

(networks only) 

"To Distribute Audit Configuration Files to a Network of Workstations"

Set security attributes 

"To Protect an Audit File System"

Security Administrator's Audit Setup Tasks - Advanced

Table 2-3 Advanced Auditing Setup by the Security Administrator

Task 

For the procedure, see...  

On first workstation 

 

Edit audit_event file  

 

"To Add Audit Events"

"To Change Event-Class Mappings"

Edit audit_class file  

"To Add Audit Classes"

Copy for distribution (networks only) 

"To Distribute Audit Configuration Files to a Network of Workstations"