Trusted Solaris Audit Administration

To Set Audit Class Mappings for Attributable Events

  1. First, as role secadmin at label admin_low, check to see if the kernel preselection mask matches the class mappings in the flags: field of the audit_control(4) file by issuing the command:


    $ auditconfig -chkconf
    

  2. If the runtime class mappings differ from the kernel cache, issue the command:


    $ auditconfig -conf