Trusted Solaris Audit Administration

To Create an Audit Directory

  1. As admin, at label admin_high, remount the local audit file systems.

    Follow the procedure in To Create an Admin_High Workspace to get an admin_high process.

    For example, on the audit file server egret:


    egret$ mount /etc/security/audit/egret
    egret$ mount /etc/security/audit/egret.1
    egret$ mount /etc/security/audit/egret.2
    egret$ mount /etc/security/audit/egret.3
    

    Similarly, on the system willet:


    willet$ mount /etc/security/audit/willet
    
  2. Create a directory named files at the top of each mounted audit partition.

    For example, on the audit file server egret:


    egret$ mkdir /etc/security/audit/egret/files
    egret$ mkdir /etc/security/audit/egret.1/files
    egret$ mkdir /etc/security/audit/egret.2/files
    egret$ mkdir /etc/security/audit/egret.3/files
    

    On the system willet:


    willet$ mkdir /etc/security/audit/willet/files