Trusted Solaris Audit Administration

To Prevent the sequence Token from Being Part of Audit Records

  1. To remove the seq audit policy dynamically, on the command line, as role secadmin at label admin_low:

    $ auditconfig -setpolicy -seq
    $ auditconfig -getpolicy

  2. To remove the seq audit policy from the audit_startup file, as role secadmin at label admin_low:

    auditconfig -setpolicy +slabel