Trusted Solaris Audit Administration

To Set Audit Class Mappings for Non-Attributable Audit Events

  1. First, as role secadmin at label admin_low, check to see if the kernel preselection mask matches the nonattributable events in the naflags: field of the audit_control(4) file by issuing the command:


    $ auditconfig -getkmask
    

  2. If they differ, issue the command:


    $ auditconfig -setkmaskac