On a distributed system, if many workstations have lost their audit daemon, bring up the audit daemons in order.
As role secadmin, execute the command /usr/sbin/auditd in an admin_high
shell on the audit administration server, then on the audit servers, and finally on the audit clients.
$ /usr/sbin/auditd |
If you are unfamiliar with creating an admin_high
shell, see To Create an Admin_High Workspace.