This token is generated by the audit daemon to mark the beginning of a new audit trail file and the end of an old file as the old file becomes deactivated. The audit record containing this token links successive audit files into one audit trail. The fields are:
A token ID
A time and date stamp of a file opening or closing
A byte count of the file name (does not show)
The file name
A file token is displayed by praudit as follows:
file,Tue Sep 1 13:32:42 1992, + 79249 msec, /baudit/localhost/files/19920901202558.19920901203241.quisp |