SunSHIELD Basic Security Module Guide
    
A
 
 -a option of auditreduce command ( Index Term Link )
 
 access audit record ( Index Term Link )
 
 acct audit record ( Index Term Link )
 
 ad audit flag ( Index Term Link )
 
 adding devices ( Index Term Link )
 
 adjtime audit record ( Index Term Link )
 
 administering auditing
  See also audit records; audit tokens; audit trail
  audit administration account ( Index Term Link ) ( Index Term Link )
  audit classes
   auditconfig command options ( Index Term Link )
   changing definitions ( Index Term Link )
   flags and definitions ( Index Term Link ) ( Index Term Link )
   mapping events ( Index Term Link ) ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
   selecting for auditing ( Index Term Link )
  audit_control file
   audit_user file modification ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
   prefixes in flags line ( Index Term Link ) ( Index Term Link )
   problem with contents ( Index Term Link )
  audit events
   audit tokens ( Index Term Link )
   auditconfig command options ( Index Term Link ) ( Index Term Link )
   categories ( Index Term Link )
   event-to-system call translation table ( Index Term Link ) ( Index Term Link )
   including in audit trail ( Index Term Link )
   kernel events ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   mapping to classes ( Index Term Link ) ( Index Term Link )
   numbers ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
   record formats and ( Index Term Link )
   user-level events ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit files ( Index Term Link ) ( Index Term Link )
   auditreduce command ( Index Term Link ) ( Index Term Link )
   combining ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   copying login/logout messages to single file ( Index Term Link ) ( Index Term Link )
   directory locations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   displaying in entirety ( Index Term Link )
   file token ( Index Term Link ) ( Index Term Link )
   managing size of ( Index Term Link )
   minimum free space for file systems ( Index Term Link )
   names ( Index Term Link ) ( Index Term Link )
   nonactive files marked not_terminated ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   order for opening ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
   permissions ( Index Term Link )
   printing ( Index Term Link )
   reducing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   reducing storage-space requirements ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   switching to new file ( Index Term Link )
   time stamps ( Index Term Link )
  audit flags ( Index Term Link ) ( Index Term Link )
   audit_control file line ( Index Term Link )
   audit_user file ( Index Term Link ) ( Index Term Link )
   auditconfig command options ( Index Term Link )
   definitions ( Index Term Link ) ( Index Term Link )
   machine-wide ( Index Term Link ) ( Index Term Link )
   overview ( Index Term Link )
   policy flags ( Index Term Link )
   prefixes ( Index Term Link ) ( Index Term Link )
   process preselection mask ( Index Term Link )
   syntax ( Index Term Link ) ( Index Term Link )
  audit partitions ( Index Term Link ) ( Index Term Link )
  audit records ( Index Term Link ) ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link )
   audit daemon's role ( Index Term Link ) ( Index Term Link )
   audit_data file ( Index Term Link )
   directory suitability ( Index Term Link )
   managing audit file size ( Index Term Link )
   overview ( Index Term Link )
  audit trail overflow prevention ( Index Term Link ) ( Index Term Link )
  audit_user file audit fields ( Index Term Link ) ( Index Term Link )
  audit_warn script ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  auditreduce command ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   -a option ( Index Term Link )
   -b option ( Index Term Link )
   capabilities ( Index Term Link )
   cleaning not_terminated files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   -d option ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   distributed systems ( Index Term Link )
   examples ( Index Term Link ) ( Index Term Link )
   -O option ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   options ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   time stamp use ( Index Term Link )
   without options ( Index Term Link ) ( Index Term Link )
  configuration
   audit trail overflow prevention ( Index Term Link ) ( Index Term Link )
   auditconfig command ( Index Term Link ) ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
   planning ( Index Term Link ) ( Index Term Link )
   setting audit policies ( Index Term Link )
  cost control ( Index Term Link ) ( Index Term Link )
   analysis ( Index Term Link )
   processing time ( Index Term Link )
   storage ( Index Term Link ) ( Index Term Link )
  efficiency ( Index Term Link ) ( Index Term Link )
  normal users ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  process audit characteristics ( Index Term Link ) ( Index Term Link )
   audit ID ( Index Term Link )
   audit session ID ( Index Term Link )
   process preselection mask ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   terminal ID ( Index Term Link )
  startup ( Index Term Link )
 
 administrative audit class ( Index Term Link )
 
 all
  audit class ( Index Term Link )
  audit flag
   caution for using ( Index Term Link )
   described ( Index Term Link )
  in user audit fields ( Index Term Link )
 
 allhard string with audit_warn script ( Index Term Link ) ( Index Term Link )
 
 allocatable devices
  See device allocation
 
 allocate audit record
  allocate-list device failure ( Index Term Link )
  allocate-list device success ( Index Term Link )
  deallocate device ( Index Term Link )
  deallocate device failure ( Index Term Link )
  device allocate failure ( Index Term Link )
  device allocate success ( Index Term Link )
 
 allocate command
  See also device allocation
  how the allocate mechanism works ( Index Term Link ) ( Index Term Link )
  options ( Index Term Link )
  using ( Index Term Link ) ( Index Term Link )
 
 allocate error state ( Index Term Link ) ( Index Term Link )
 
 allocating devices
  See device allocation
 
 allsoft string with audit_warn script ( Index Term Link )
 
 always-audit flags
  described ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
 
 analysis ( Index Term Link ) ( Index Term Link )
  audit record format ( Index Term Link ) ( Index Term Link )
  auditing features ( Index Term Link ) ( Index Term Link )
  auditreduce command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  costs ( Index Term Link )
  praudit command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  tools ( Index Term Link ) ( Index Term Link )
 
 ap audit flag ( Index Term Link )
 
 application audit class ( Index Term Link )
 
 arbitrary token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 Archive tape drive clean script ( Index Term Link )
 
 arg token ( Index Term Link ) ( Index Term Link )
 
 arge policy
  exec_env token and ( Index Term Link )
  flag ( Index Term Link )
 
 argv policy
  exec_args token and ( Index Term Link )
  flag ( Index Term Link )
 
 asterisk (*) in device_allocate file ( Index Term Link ) ( Index Term Link )
 
 at audit record
  at-create crontab ( Index Term Link )
  at-delete atjob ( Index Term Link )
  at-permission ( Index Term Link )
 
 attr token ( Index Term Link ) ( Index Term Link )
 
 audio_clean script ( Index Term Link )
 
 audio devices, See device allocation, device-clean scripts ( Index Term Link )
  device-clean scripts ( Index Term Link )
 
 AUDIO_DRAIN ioctl system call ( Index Term Link )
 
 AUDIO_SETINFO ioctl system call ( Index Term Link )
 
 AUDIOGETREG ioctl system call ( Index Term Link )
 
 AUDIOSETREG ioctl system call ( Index Term Link )
 
 audit -n command ( Index Term Link )
 
 audit -s command
  preselection mask for existing processes ( Index Term Link )
  rereading audit files ( Index Term Link )
  resetting directory pointer ( Index Term Link ) ( Index Term Link )
 
 audit -t command ( Index Term Link )
 
 audit administration account ( Index Term Link ) ( Index Term Link )
 
 audit attributes
  See audit tokens
 
 audit audit record ( Index Term Link )
 
 audit classes
  auditconfig command options ( Index Term Link )
  changing definitions ( Index Term Link )
  flags and definitions ( Index Term Link ) ( Index Term Link )
  mapping events ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  selecting for auditing ( Index Term Link )
 
 audit_control file
  audit daemon rereading after editing ( Index Term Link )
  audit_user file modification ( Index Term Link )
  dir: line
   described ( Index Term Link )
   examples ( Index Term Link ) ( Index Term Link )
   files subdirectory ( Index Term Link )
  examples ( Index Term Link ) ( Index Term Link )
  flags: line
   described ( Index Term Link )
   prefixes in ( Index Term Link ) ( Index Term Link )
   process preselection mask ( Index Term Link )
  minfree: line
   audit_warn condition ( Index Term Link )
   described ( Index Term Link )
  naflags: line ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  prefixes in flags line ( Index Term Link ) ( Index Term Link )
  problem with contents ( Index Term Link )
 
 audit daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link )
  directories suitable to ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
  terminating ( Index Term Link )
 
 audit_data file ( Index Term Link )
 
 audit_event file
  See also audit events
  audit event type ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
 
 audit events
  See also audit classes
  audit_event file
   audit event type ( Index Term Link )
   overview ( Index Term Link ) ( Index Term Link )
  categories ( Index Term Link )
  event-to-system call translation table ( Index Term Link ) ( Index Term Link )
  including in audit trail ( Index Term Link )
  kernel events
   audit tokens ( Index Term Link )
   auditconfig command options ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link )
  mapping to classes ( Index Term Link ) ( Index Term Link )
  numbers ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  record formats and ( Index Term Link )
  user-level events
   audit tokens ( Index Term Link )
   auditconfig command options ( Index Term Link )
   described ( Index Term Link )
 
 audit files
  See also audit trail; directories
  auditreduce command ( Index Term Link ) ( Index Term Link )
  combining ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  copying login/logout messages to single file ( Index Term Link ) ( Index Term Link )
  directory locations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  displaying in entirety ( Index Term Link )
  file token ( Index Term Link ) ( Index Term Link )
  managing size of ( Index Term Link )
  minimum free space for file systems ( Index Term Link )
  names ( Index Term Link ) ( Index Term Link )
   closed files ( Index Term Link )
   form ( Index Term Link ) ( Index Term Link )
   still-active files ( Index Term Link ) ( Index Term Link )
   time stamps ( Index Term Link )
   use ( Index Term Link )
  nonactive files marked not_terminated ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  order for opening ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  permissions ( Index Term Link )
  printing ( Index Term Link )
  reducing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  reducing storage-space requirements ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  switching to new file ( Index Term Link )
  time stamps ( Index Term Link )
 
 audit flags ( Index Term Link ) ( Index Term Link )
  audit_control file line ( Index Term Link )
  audit_user file ( Index Term Link ) ( Index Term Link )
  auditconfig command options ( Index Term Link )
  definitions ( Index Term Link ) ( Index Term Link )
  machine-wide ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link )
  policy flags ( Index Term Link )
  prefixes ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
  syntax ( Index Term Link ) ( Index Term Link )
 
 audit ID ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 audit log files
  See audit files
 
 audit partitions ( Index Term Link ) ( Index Term Link )
 
 audit policies
  See also audit flags
  auditconfig options ( Index Term Link )
  setting ( Index Term Link )
 
 audit records
  See also audit tokens; specific audit records
  audit directories full ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  converting to human-readable format ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  displaying ( Index Term Link )
  format or structure ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  kernel-level generated ( Index Term Link ) ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  policy flags ( Index Term Link )
  reducing audit files ( Index Term Link )
  selecting ( Index Term Link )
  self-contained records ( Index Term Link )
  tools ( Index Term Link ) ( Index Term Link )
  user-level generated ( Index Term Link ) ( Index Term Link )
 
 audit server mount-point path names ( Index Term Link )
 
 audit session ID ( Index Term Link ) ( Index Term Link )
 
 audit_startup file ( Index Term Link )
 
 audit threshold ( Index Term Link )
 
 audit tokens
  arbitrary token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  arg token ( Index Term Link ) ( Index Term Link )
  attr token ( Index Term Link ) ( Index Term Link )
  audit record format ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link )
  exec_args token ( Index Term Link )
  exec_env token ( Index Term Link )
  exit token ( Index Term Link ) ( Index Term Link )
  file token ( Index Term Link ) ( Index Term Link )
  groups token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  header token ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  in_addr token ( Index Term Link ) ( Index Term Link )
  ip token ( Index Term Link ) ( Index Term Link )
  ipc_perm token ( Index Term Link ) ( Index Term Link )
  ipc token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  iport token ( Index Term Link ) ( Index Term Link )
  newgroups token ( Index Term Link )
  opaque token ( Index Term Link ) ( Index Term Link )
  order in audit record ( Index Term Link )
  path token ( Index Term Link ) ( Index Term Link )
  policy flags ( Index Term Link )
  process token ( Index Term Link ) ( Index Term Link )
  return token ( Index Term Link ) ( Index Term Link )
  seq token ( Index Term Link ) ( Index Term Link )
  socket-inet token ( Index Term Link )
  socket token ( Index Term Link ) ( Index Term Link )
  subject token ( Index Term Link ) ( Index Term Link )
  table of ( Index Term Link )
  text token ( Index Term Link ) ( Index Term Link )
  trailer token ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  types ( Index Term Link ) ( Index Term Link )
 
 audit trail
  See also audit files, audit records; audit tokens
  analysis ( Index Term Link ) ( Index Term Link )
   audit record format ( Index Term Link ) ( Index Term Link )
   auditing features ( Index Term Link ) ( Index Term Link )
   auditreduce command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   costs ( Index Term Link )
   praudit command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   tools ( Index Term Link ) ( Index Term Link )
  creating ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit daemon's role ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   audit_data file ( Index Term Link )
   directory suitability ( Index Term Link )
   managing audit file size ( Index Term Link )
   overview ( Index Term Link )
  directory locations ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  events included ( Index Term Link )
  merging all files ( Index Term Link ) ( Index Term Link )
  monitoring in real time ( Index Term Link )
  overflow prevention ( Index Term Link ) ( Index Term Link )
 
 audit_user file
  prefixes for flags ( Index Term Link ) ( Index Term Link )
  process preselection mask ( Index Term Link )
  user audit fields ( Index Term Link ) ( Index Term Link )
 
 audit_warn script ( Index Term Link ) ( Index Term Link )
  allhard string ( Index Term Link ) ( Index Term Link )
  allsoft string ( Index Term Link )
  audit daemon execution of ( Index Term Link )
  auditsvc string ( Index Term Link )
  conditions invoking ( Index Term Link ) ( Index Term Link )
  described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ebusy string ( Index Term Link )
  hard string ( Index Term Link )
  postsigterm string ( Index Term Link )
  soft string ( Index Term Link )
  tmpfile string ( Index Term Link )
 
 auditconfig command
  audit flags as arguments ( Index Term Link )
  options ( Index Term Link ) ( Index Term Link )
  prefixes for flags ( Index Term Link ) ( Index Term Link )
  reducing storage-space requirements ( Index Term Link )
 
 auditd daemon
  audit_startup file ( Index Term Link )
  audit trail creation ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  audit_warn script
   conditions invoking ( Index Term Link ) ( Index Term Link )
   described ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
   execution of ( Index Term Link )
  directories suitable to ( Index Term Link )
  enabling auditing ( Index Term Link )
  functions ( Index Term Link )
  order audit files are opened ( Index Term Link )
  rereading the audit_control file ( Index Term Link )
  terminating ( Index Term Link )
 
 auditing
  See administering auditing; audit trail
 
 auditon audit record
  A_GETCAR command ( Index Term Link )
  A_GETCLASS command ( Index Term Link )
  A_GETCOND command ( Index Term Link )
  A_GETCWD command ( Index Term Link )
  A_GETKMASK command ( Index Term Link )
  A_GETSTAT command ( Index Term Link )
  A_GPOLICY command ( Index Term Link )
  A_GQCTRL command ( Index Term Link )
  A_SETCLASS command ( Index Term Link )
  A_SETCOND command ( Index Term Link )
  A_SETKMASK command ( Index Term Link )
  A_SETSMASK command ( Index Term Link )
  A_SETSTAT command ( Index Term Link )
  A_SETUMASK command ( Index Term Link )
  A_SPOLICY command ( Index Term Link )
  A_SQCTRL command ( Index Term Link )
 
 auditreduce command ( Index Term Link ) ( Index Term Link )
  -a option ( Index Term Link )
  -b option ( Index Term Link )
  capabilities ( Index Term Link )
  cleaning not_terminated files ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  -d option ( Index Term Link )
  described ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  distributed systems ( Index Term Link )
  examples ( Index Term Link ) ( Index Term Link )
  -m option ( Index Term Link )
  -O option ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  options ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  time stamp use ( Index Term Link )
  without options ( Index Term Link ) ( Index Term Link )
 
 auditsvc
  audit record ( Index Term Link )
  system call
   fails ( Index Term Link ) ( Index Term Link )
 
 AUE_... names ( Index Term Link ) ( Index Term Link )
  event-to-system call translation table ( Index Term Link ) ( Index Term Link )
 
 automatically enabling auditing ( Index Term Link )