Trusted Solaris Audit Administration

To Set User Exceptions to the Audit Flags

As role secadmin, at label admin_low, enter user exceptions to system-wide audit flags in the audit_user(4) file.

  1. Open the System_Admin folder from the Application Manager.

  2. Double-click the Audit Users action.

  3. Enter the user exceptions, write the file, and exit the editor.

    For example, the following entry audits the role root for logins and logouts, and never audits the fc class, even if it is being audited for the workstation. The jane entry audits her for all flags specified in the audit_control file except for successful file_read events. Null events, no, are never audited.

    # User Level Audit User File
    #
    # File Format
    #
    #       username:always:never
    #
    root:lo:no,fc
    jane:all,^+fr:no