Trusted Solaris Audit Administration

Appendix A Event-to-Class Mappings

This appendix lists audit events by audit class. See the file /etc/security/audit_event for a list of events by audit event number.

Audit Events Listed by Audit Class

The Trusted Solaris environment provides the audit classes listed alphabetically by Short Name in the following table. The classes are listed in the file /etc/security/audit_class.

Table A–1 Trusted Solaris Audit Classes (Default)

Short Name 

Long Name 

Audit Mask 

List of Events per Class 

aa 

Audit administration 

0x00040000

Table A–2

ad 

Administrative 

0x000f0000

Table A–3

ao 

Other administration 

0x00080000

Table A–4

all 

All classes 

0xffffffff

 

ap 

Application 

0x00004000

Table A–6

as 

System-wide administration 

0x00020000

Table A–24

ax 

X server 

0x00002000

Table A–26

cl 

File close 

0x00000040

Table A–7

fa 

File attribute access 

0x00000004

Table A–8

fc 

File create 

0x00000010

Table A–9

fd 

File delete 

0x00000020

Table A–10

fm 

File attribute modify 

0x00000008

Table A–11

fn 

Fcntl 

0x40000000

Table A–12

fr 

File read 

0x00000001

Table A–13

fw 

File write 

0x00000002

Table A–14

il 

Internal label info 

0x00010000  

Obsolete. 

io 

Ioctl 

0x20000000

Table A–15

ip 

Ipc 

0x00000200

Table A–16

lo 

Login or logout 

0x00001000

Table A–17

na 

Non-attribute 

0x00000400

Table A–18

no 

Invalid class 

0x00000000

Table A–19

nt 

Network 

0x00000100

Table A–20

ot 

Other 

0x80000000

Table A–21

pc 

Process 

0x00300000

No defined events. 

pm 

Process modify 

0x00200000

Table A–22

ps 

Process start/stop 

0x00100000

Table A–23

ss 

Change system state 

0x00010000

Table A–25

xa 

X - Allowed information flows 

0x40000000

Table A–27

xc 

X - Object create/destroy 

0x20000000

Table A–28

xl 

X - Client login/logout 

0x08000000

Table A–29

xp 

X - Privileged operations 

0x10000000

Table A–30

xs 

X - Operations that fail silently 

0x80000000

Table A–31

xx 

X - All X events 

0xf8000000

See the individual X classes. 

For more information about the classes, see the audit_class(4) man page.

Events in Audit Class aa

The following table lists in alphabetical order the audit administration class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–2 Audit Administration Audit Events (Default)

Audit Event Number and Event 

Where Described 

224

AUE_AUDITON_GETCAR

Table B–9

231

AUE_AUDITON_GETCLASS

Table B–10

229

AUE_AUDITON_GETCOND

Table B–11

223

AUE_AUDITON_GETCWD

Table B–12

221

AUE_AUDITON_GETKMASK

Table B–13

225

AUE_AUDITON_GETSTAT

Table B–14

141

AUE_AUDITON_GPOLICY

Table B–15

145

AUE_AUDITON_GQCTRL

Table B–16

139

AUE_AUDITON_GTERMID

No longer supported. 

144

AUE_AUDITON_SESTATE

No longer supported. 

232

AUE_AUDITON_SETCLASS

Table B–17

230

AUE_AUDITON_SETCOND

Table B–18

222

AUE_AUDITON_SETKMASK

Table B–19

228

AUE_AUDITON_SETSMASK

Table B–20

226

AUE_AUDITON_SETSTAT

Table B–21

227

AUE_AUDITON_SETUMASK

Table B–22

142

AUE_AUDITON_SPOLICY

Table B–23

146

AUE_AUDITON_SQCTRL

Table B–24

140

AUE_AUDITON_STERMID

No longer supported. 

529

AUE_AUDITPSA

Table B–25

150

AUE_AUDITSTAT

Table B–26

136

AUE_AUDITSVC

Table B–27

530

AUE_FAUDITPSA

Table B–40

132

AUE_GETAUDIT

Table B–51

130

AUE_GETAUID

Table B–53

147

AUE_GETKERNSTATE

No longer supported. 

149

AUE_GETPORTAUDIT

Table B–63

134

AUE_GETUSERAUDIT

No longer supported. 

133

AUE_SETAUDIT

Table B–138

131

AUE_SETAUID

Table B–140

148

AUE_SETKERNSTATE

No longer supported. 

135

AUE_SETUSERAUDIT

No longer supported. 

9016

AUE_audit

Table B–239

9015

AUE_auditwrite

Table B–240

Events in Audit Class ad

The following table lists in alphabetical order the administrative class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–3 Administrative Audit Events (Default)

Audit Event Number and Event 

Where Described 

267

AUE_GETAUDIT_ADDR

Table B–52

263

AUE_PROCESSOR_BIND

Table B–109

266

AUE_SETAUDIT_ADDR

Table B–139

268

AUE_UMOUNT2

Table B–179

6166

AUE_init_solaris

 

6167

AUE_uadmin_solaris

 

6168

AUE_shutdown_solaris

 

6169

AUE_poweroff_solaris

 

6170

AUE_crontab_mod

 

6207

AUE_create_user

 

6208

AUE_modify_user

 

6209

AUE_delete_user

 

6210

AUE_disable_user

 

6211

AUE_enable_user

 

6220

AUE_smserverd

 

6214

AUE_kadmind_auth

 

6215

AUE_kadmind_unauth

 

Events in Audit Class ao

The following table lists in alphabetical order the other administration class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–4 Administrative Other Audit Events (Default)

Audit Event Number and Event 

Where Described 

61

AUE_EXPORTFS

Table B–297

62

AUE_MOUNT

Table B–82

115

AUE_NFSSVC_EXIT

nfssvc(2) 

58

AUE_NFS_GETFH

nfs_getfh(2) 

53

AUE_NFS_SVC

nfs_svc(2) 

60

AUE_QUOTACTL

Table B–115

12

AUE_UMOUNT

Table B–178

56

AUE_UNMOUNT

No longer supported. 

233

AUE_UTSSYS

Table B–182

6200

AUE_allocate_succ

Table B–232

6201

AUE_allocate_fail

Table B–233

6144

AUE_at_create

Table B–236

6145

AUE_at_delete

Table B–237

6146

AUE_at_perm

Table B–238

9034

AUE_automountd_mismatch

Table B–241

9033

AUE_automountd_mount

Table B–242

9029

AUE_chroot_cmd

Table B–243

6147

AUE_cron_invoke

Table B–246

6148

AUE_crontab_create

Table B–244

6149

AUE_crontab_delete

Table B–245

6150

AUE_crontab_perm

Table B–248

6202

AUE_deallocate_succ

Table B–250

6203

AUE_deallocate_fail

Table B–251

6181

AUE_filesystem_add

Table B–300

6182

AUE_filesystem_delete

Table B–300

6183

AUE_filesystem_modify

Table B–300

9031

AUE_fuser

Table B–255

6205

AUE_listdevice_succ

Table B–234

6206

AUE_listdevice_fail

Table B–235

9044

AUE_lp_cancel

Table B–268

9045

AUE_lp_status

 

6184

AUE_network_add

Table B–299

6185

AUE_network_delete

Table B–299

6186

AUE_network_modify

Table B–299

6187

AUE_printer_add

Table B–278

6188

AUE_printer_delete

Table B–278

6189

AUE_printer_modify

Table B–278

6180

AUE_prof_cmd

Table B–273

6173

AUE_role_login

Table B–291

6190

AUE_scheduledjob_add

Table B–302

6191

AUE_scheduledjob_delete

Table B–302

6192

AUE_scheduledjob_modify

Table B–302

6193

AUE_serialport_add

Table B–301

6194

AUE_serialport_delete

Table B–301

6195

AUE_serialport_modify

Table B–301

9013

AUE_sendmail_deliver

Table B–293

9014

AUE_sendmail_defer

Table B–293

9012

AUE_sendmail_upgrade

Table B–294

9322

AUE_te_modsysfiles

Table B–231

6199

AUE_uauth

Table B–308

9024

AUE_uname_set

Table B–311

6196

AUE_usermgr_add

Table B–303

6197

AUE_usermgr_delete

Table B–303

6198

AUE_usermgr_modify

Table B–303

Table A–5 Administrative Other Audit Events (Obsolete)

Audit Event Number and Event 

Where Described 

9319

AUE_dm_add

Table B–249

9320

AUE_dm_del

9321

AUE_dm_mod

9307

AUE_gm_add_grp

Table B–256

9308

AUE_gm_del_grp

9309

AUE_gm_mod_grp

9310

AUE_hm_add_host

Table B–258

9311

AUE_hm_del_host

9312

AUE_hm_mod_host

9313

AUE_hm_set_def

9009

AUE_pfsh_priv

Table B–275

9008

AUE_pfsh_trusted_nopriv

9007

AUE_pfsh_trusted_priv

9316

AUE_pm_add

Table B–279

9318

AUE_pm_del_prn

9317

AUE_pm_mod_prn

9306

AUE_pm_add_prof

Table B–280

9306

AUE_pm_del_prof

Table B–281

9305

AUE_pm_mod_prof

Table B–282

9315

AUE_sm_del_ser

Table B–295

9314

AUE_sm_mod_ser

 

9302

AUE_um_add_user

Table B–310

9301

AUE_um_del_user

9300

AUE_um_mod_user

9303

AUE_um_set_def

Events in Audit Class ap

The following table lists in alphabetical order the application class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–6 Application Audit Events (Default)

Audit Event Number and Event 

Where Described 

9010

AUE_pfsh_nopriv

Table B–275

9035

AUE_sl_change

Table B–304

Events in Audit Class cl

The following table lists in alphabetical order the file close class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–7 File Close Audit Events (Default)

Audit Event Number and Event 

Where Described 

112

AUE_CLOSE

Table B–34

213

AUE_MUNMAP

Table B–91

Events in Audit Class fa

The following table lists in alphabetical order the file attribute access class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–8 File Attribute Access Audit Events (Default)

Audit Event Number and Event 

Where Described 

14

AUE_ACCESS

Table B–5

220

AUE_AUDITSYS

Placeholder 

66

AUE_BSMSYS

Placeholder 

543

AUE_FGETCMWLABEL

Table B–55

55

AUE_FSTATFS

Table B–50

545

AUE_GETCMWFSRANGE

Table B–54

546

AUE_GETCMWLABEL

Table B–55

547

AUE_GETFILEPRIV

Table B–57

554

AUE_GETMLDADORN

Table B–58

555

AUE_GETSLDNAME

Table B–66

548

AUE_LGETCMWLABEL

Table B–55

17

AUE_LSTAT

Table B–71

236

AUE_LXSTAT

Table B–72

556

AUE_MLDLSTAT

Obsolete. 

557

AUE_MLDSTAT

64

AUE_MSGSYS

Placeholder 

3

AUE_OPEN

Placeholder 

199

AUE_OSTAT

No longer supported. 

71

AUE_PATHCONF

Table B–105

67

AUE_RFSSYS

Placeholder 

63

AUE_SEMSYS

Placeholder 

65

AUE_SHMSYS

Placeholder 

16

AUE_STAT

Table B–167

54

AUE_STATFS

234

AUE_STATVFS

70

AUE_VPIXSYS

Placeholder 

235

AUE_XSTAT

Table B–188

Events in Audit Class fc

The following table lists in alphabetical order the file create class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–9 File Create Audit Events (Default)

Audit Event Number and Event 

Where Described 

111

AUE_CORE

Table B–111

4

AUE_CREAT

Table B–35

532

AUE_FGETSLDNAME

Table B–46

5

AUE_LINK

Table B–70

47

AUE_MKDIR

Table B–74

9

AUE_MKNOD

Table B–75

73

AUE_OPEN_RC

Table B–94

75

AUE_OPEN_RTC

Table B–95

81

AUE_OPEN_RWC

Table B–98

83

AUE_OPEN_RWTC

Table B–99

77

AUE_OPEN_WC

Table B–102

79

AUE_OPEN_WTC

Table B–103

42

AUE_RENAME

Table B–119

48

AUE_RMDIR

Table B–120

21

AUE_SYMLINK

Table B–169

240

AUE_XMKNOD

Table B–187

Events in Audit Class fd

The following table lists in alphabetical order the file delete class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–10 File Delete Audit Events (Default)

Audit Event Number and Event 

Where Described 

44

AUE_FTRUNCATE

No longer supported. 

74

AUE_OPEN_RT

Table B–96

75

AUE_OPEN_RTC

Table B–95

82

AUE_OPEN_RWT

Table B–100

83

AUE_OPEN_RWTC

Table B–99

78

AUE_OPEN_WT

Table B–104

79

AUE_OPEN_WTC

Table B–103

42

AUE_RENAME

Table B–119

6

AUE_UNLINK

Table B–180

Events in Audit Class fm

The following table lists in alphabetical order the file attribute modify class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–11 File Attribute Modify Audit Events (Default)

Audit Event Number and Event 

Where Described 

251

AUE_ACLSET

Table B–137

11

AUE_CHOWN

Table B–30

252

AUE_FACLSET

Table B–137

39

AUE_FCHMOD

Table B–42

38

AUE_FCHOWN

Table B–43

45

AUE_FLOCK

Placeholder 

544

AUE_FSETCMWLABEL

Table B–142

523

AUE_FSETFATTRFLAG

Table B–49

158

AUE_IOCTL

Table B–67

237

AUE_LCHOWN

Table B–69

525

AUE_LSETCMWLABEL

Table B–142

19

AUE_MCTL

No longer supported. 

524

AUE_MLDSETFATTRFLAG

Table B–76

542

AUE_SETCLEARANCE

Table B–141

549

AUE_SETCMWLABEL

Table B–142

541

AUE_SETCMWPLABEL

Table B–143

522

AUE_SETFATTRFLAG

Table B–146

550

AUE_SETFILEPRIV

Table B–147

551

AUE_SETPROCPRIV

Table B–151

202

AUE_UTIME

Table B–181

49

AUE_UTIMES

 

552

AUE_WRITEL

Table B–186

553

AUE_WRITEVL

9037

AUE_dtfile_copy

Table B–253

9038

AUE_dtfile_move

Table B–253

Events in Audit Class fn

The following table lists in alphabetical order the fcntl class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–12 Fcntl Audit Events (Default)

Audit Event Number and Event 

Where Described 

30

AUE_FCNTL

Table B–45

Events in Audit Class fr

The following table lists in alphabetical order the file read class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–13 File Read Audit Events (Default)

Audit Event Number and Event 

Where Described 

72

AUE_OPEN_R

Table B–93

73

AUE_OPEN_RC

Table B–94

74

AUE_OPEN_RT

Table B–96

75

AUE_OPEN_RTC

Table B–95

80

AUE_OPEN_RW

Table B–97

81

AUE_OPEN_RWC

Table B–98

82

AUE_OPEN_RWT

Table B–100

83

AUE_OPEN_RWTC

Table B–99

22

AUE_READLINK

Table B–117

Events in Audit Class fw

The following table lists in alphabetical order the file read class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–14 File Write Audit Events (Default)

Audit Event Number and Event 

Where Described 

80

AUE_OPEN_RW

Table B–97

81

AUE_OPEN_RWC

Table B–98

82

AUE_OPEN_RWT

Table B–100

83

AUE_OPEN_RWTC

Table B–99

76

AUE_OPEN_W

Table B–101

77

AUE_OPEN_WC

Table B–102

78

AUE_OPEN_WT

Table B–104

79

AUE_OPEN_WTC

Table B–103

Events in Audit Class io

The following table lists the audit event in the ioctl class provided in the Trusted Solaris 8 4/01 release.

Table A–15 Ioctl Audit Events (Default)

Audit Event Number and Event 

Where Described 

158

AUE_IOCTL

Table B–67

Events in Audit Class ip

The following table lists in alphabetical order the ipc class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–16 IPC Audit Events (Default)

Audit Event Number and Event 

Where Described 

260 

AUE_DOORFS_DOOR_BIND

doorfs(2) - DOOR_BIND 

254 

AUE_DOORFS_DOOR_CALL

doorfs(2) - DOOR_CALL 

256 

AUE_DOORFS_DOOR_CREATE

doorfs(2) - DOOR_CREATE 

258 

AUE_DOORFS_DOOR_INFO

doorfs(2) - DOOR_INFO 

255 

AUE_DOORFS_DOOR_RETURN

doorfs(2) - DOOR_RETURN 

257 

AUE_DOORFS_DOOR_REVOKE

doorfs(2) - DOOR_REVOKE 

259 

AUE_DOORFS_DOOR_CRED

doorfs(2) - DOOR_CRED 

261 

AUE_DOORFS_DOOR_UNBIND

doorfs(2) - DOOR_UNBIND 

514

AUE_GETMSGQCMWLABEL

Table B–61

515

AUE_GETSEMCMWLABEL

Table B–64

516

AUE_GETSHMCMWLABEL

Table B–65

84

AUE_MSGCTL

Illegal command 

85

AUE_MSGCTL_RMID

Table B–84

86

AUE_MSGCTL_SET

Table B–85

87

AUE_MSGCTL_STAT

Table B–86

88

AUE_MSGGET

Table B–87

174

AUE_MSGGETL

Table B–88

89

AUE_MSGRCV

Table B–89

175

AUE_MSGRCVL

Table B–89

90

AUE_MSGSND

Table B–90

176

AUE_MSGSNDL

Obsolete. 

98

AUE_SEMCTL

Illegal command 

105

AUE_SEMCTL_GETALL

Table B–122

102

AUE_SEMCTL_GETNCNT

Table B–123

103

AUE_SEMCTL_GETPID

Table B–124

104

AUE_SEMCTL_GETVAL

Table B–125

106

AUE_SEMCTL_GETZCNT

Table B–126

99

AUE_SEMCTL_RMID

Table B–127

100

AUE_SEMCTL_SET

Table B–128

108

AUE_SEMCTL_SETALL

Table B–129

107

AUE_SEMCTL_SETVAL

Table B–130

101

AUE_SEMCTL_STAT

Table B–131

109

AUE_SEMGET

Table B–132

177

AUE_SEMGETL

Table B–133

110

AUE_SEMOP

Table B–134

517

AUE_SEMOPL

Obsolete. 

96

AUE_SHMAT

Table B–157

91

AUE_SHMCTL

Placeholder 

92

AUE_SHMCTL_RMID

Table B–159

93

AUE_SHMCTL_SET

Table B–160

94

AUE_SHMCTL_STAT

Table B–161

97

AUE_SHMDT

Table B–162

95

AUE_SHMGET

Table B–163

178

AUE_SHMGETL

Table B–164

Events in Audit Class lo

The following table lists in alphabetical order the login or logout class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–17 Login or Logout Audit Events (Default)

Audit Event Number and Event 

Where Described 

6123

AUE_admin_authenticate

Table B–298

6165

AUE_ftpd

Table B–260

6152

AUE_login

Table B–262

6153

AUE_logout

Table B–265

6163

AUE_passwd

Table B–272

6164

AUE_rexd

Table B–286

6162

AUE_rexecd

Table B–287

6155

AUE_rlogin

Table B–263

6173

AUE_role_login

Table B–291

6158

AUE_rshd

Table B–288

6159

AUE_su

Table B–305

6154

AUE_telnet

Table B–264

Events in Audit Class na

The following table lists in alphabetical order the non-attribute class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–18 Non-attribute Audit Events (Default)

Audit Event Number and Event 

Where Described 

153

AUE_ENTERPROM

Table B–37

154

AUE_EXITPROM

113

AUE_SYSTEMBOOT

Table B–171

6151

AUE_inetd_connect

Table B–259

6156

AUE_mountd_mount

Table B–270

6157

AUE_mountd_umount

Table B–271

Events in Audit Class no

The following table lists in alphabetical order the invalid class class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–19 Invalid Class Audit Events (Default)

Audit Event Number and Event 

Where Described 

211

AUE_AUDIT

Table B–8

209

AUE_DUP2

No longer supported. 

208

AUE_FSTAT

Table B–50

193

AUE_GETDENTS

Table B–56

13

AUE_JUNK

 

194

AUE_LSEEK

Placeholder 

518

AUE_MAC

No longer supported. 

210

AUE_MMAP

Table B–77

242

AUE_MODCTL

Placeholder 

197

AUE_NFS

Placeholder 

0

AUE_NULL

Indirect system call 

185

AUE_PIPE

Table B–106

527

AUE_PREADL

Table B–107

528

AUE_PWRITEL

Table B–186

192

AUE_READ

Table B–116

558

AUE_READL

198

AUE_READV

Placeholder 

559

AUE_READVL

Table B–116

189

AUE_RECV

Placeholder 

187

AUE_SEND

Placeholder 

186

AUE_SOCKETPAIR

Placeholder 

521

AUE_UPRIV

Table B–189

195

AUE_WRITE

Table B–185

196

AUE_WRITEV

Placeholder 

Events in Audit Class nt

The following table lists in alphabetical order the network class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–20 Network Audit Events (Default)

Audit Event Number and Event 

Where Described 

33

AUE_ACCEPT

No longer supported. 

34

AUE_BIND

No longer supported. 

32

AUE_CONNECT

No longer supported. 

217

AUE_GETMSG

Table B–59

219

AUE_GETPMSG

Table B–62

173

AUE_ONESIDE

No longer supported. 

216

AUE_PUTMSG

Table B–112

218

AUE_PUTPMSG

Table B–114

191

AUE_RECVFROM

Format unavailable. 

190

AUE_RECVMSG

Table B–118

188

AUE_SENDMSG

Table B–135

184

AUE_SENDTO

Table B–136

35

AUE_SETSOCKOPT

Table B–155

247

AUE_SOCKACCEPT

Table B–60

248

AUE_SOCKCONNECT

Table B–113

183

AUE_SOCKET

Table B–166

250

AUE_SOCKRECEIVE

Table B–60

249

AUE_SOCKSEND

Table B–113

534

AUE_TNIF

Table B–172

535

AUE_TNRH

536

AUE_TNRHTP

537

AUE_TOKMAPPER

Table B–173

Events in Audit Class ot

The following table lists in alphabetical order the other class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–21 Other Audit Events (Default)

Audit Event Number and Event 

Where Described 

238

AUE_MEMCNTL

Table B–73

Events in Audit Class pm

The following table lists in alphabetical order the process modify class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–22 Process Modify Audit Events (Default)

Audit Event Number and Event 

Where Described 

8

AUE_CHDIR

Table B–28

24

AUE_CHROOT

Table B–31

1

AUE_EXIT

Table B–39

68

AUE_FCHDIR

Table B–41

69

AUE_FCHROOT

Table B–44

15

AUE_KILL

Table B–68

52

AUE_KILLPG

No longer supported.  

203

AUE_NICE

Table B–92

204

AUE_OSETPGRP

No information. 

200

AUE_OSETUID

No longer supported.  

212

AUE_PRIOCNTLSYS

Table B–108

214

AUE_SETEGID

Table B–144

215

AUE_SETEUID

Table B–145

526

AUE_SETPATTR

Table B–149

205

AUE_SETGID

Table B–144

26

AUE_SETGROUPS

Table B–148

27

AUE_SETPGRP

Table B–150

31

AUE_SETPRIORITY

No longer supported.  

41

AUE_SETREGID

Table B–152

40

AUE_SETREUID

Table B–153

200 

AUE_SETUID - event name is AUE_OSETUID

Table B–156

36

AUE_VTRACE

Table B–184

Events in Audit Class ps

The following table lists in alphabetical order the process start/stop class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–23 Process Start/Stop Audit Events (Default)

Audit Event Number and Event 

Where Described 

7

AUE_EXEC

Table B–38

23

AUE_EXECVE

2

AUE_FORK

Table B–47

241

AUE_FORK1

526

AUE_SETPATTR

Table B–149

25

AUE_VFORK

Table B–183

9027

AUE_psradm

Table B–283

Events in Audit Class as

The following table lists in alphabetical order the system-wide administration class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–24 System-wide Administration Audit Events (Default)

Audit Event Number and Event 

Where Described 

18

AUE_ACCT

Table B–6

50

AUE_ADJTIME

Table B–7

57

AUE_ASYNC_DAEMON

 

114

AUE_ASYNC_DAEMON_EXIT

 

538

AUE_CHSTATE

Table B–32

513

AUE_CLOCK_SETTIME

Table B–33

531

AUE_DRVPOLICY

Table B–36

264

AUE_INST_SYNC

 

246

AUE_MODADDMAJ

Table B–78

245

AUE_MODCONFIG

Table B–79

243

AUE_MODLOAD

Table B–80

244

AUE_MODUNLOAD

Table B–81

533

AUE_PRIVENABLE

Table B–110

540

AUE_REMOUNT

Table B–176

59

AUE_SETDOMAINNAME

 

29

AUE_SETHOSTNAME

 

51

AUE_SETRLIMIT

Table B–154

37

AUE_SETTIMEOFDAY

 

201

AUE_STIME

Table B–168

28

AUE_SWAPON

swapon(2) 

239

AUE_SYSINFO

Table B–170

9018

AUE_add_drv

Table B–230

9025

AUE_dispadmin

Table B–252

9032

AUE_eeprom

Table B–254

9042

AUE_installf

Table B–261

9020

AUE_modload

Table B–269

9021

AUE_modunload

Table B–269

9026

AUE_pbind

Table B–274

9040

AUE_pkginstall

Table B–276

9041

AUE_pkgremove

Table B–277

9027

AUE_psradm

Table B–283

9019

AUE_rem_drv

Table B–289

9043

AUE_removef

Table B–285

9022

AUE_setuname

Table B–296

9030

AUE_swap

Table B–306

9024

AUE_uname_set

Table B–311

Events in Audit Class ss

The following table lists in alphabetical order the change system state class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–25 Change System State Audit Events (Default)

Audit Event Number and Event 

Where Described 

539

AUE_FREEZE

Table B–174

561

AUE_REBOOT

Table B–175

560

AUE_SHUTDOWN

Table B–177

6160

AUE_halt_solaris

Table B–257

6161

AUE_reboot_solaris

Table B–284

9028

AUE_run_level_change

Table B–290

9023

AUE_uadmin_cmd

Table B–307

Events in Audit Class ax

The following table lists in alphabetical order the ax class of audit events provided in the Trusted Solaris 8 4/01 release.

Table A–26 X Server Audit Events - Remainder (Default)

Audit Event Number and Event 

Where Described 

9039

AUE_sel_mgr_xfer

Table B–292

Events in Audit Class xa

The following table lists in alphabetical order the xa class of audit events provided in the Trusted Solaris 8 4/01 release. This class contains X protocols that use "default" client privileges to succeed. These privileges are listed in the file /usr/openwin/server/tsol/config.privs. The security administrator can remove privileges from this file.

Table A–27 X - Allowed Information Flows Audit Events (Default)

Audit Event Number and Event 

Where Described 

9194

AUE_ChangeHosts

Table B–226

9137

AUE_GrabServer

Table B–201

9183

AUE_InstallColormap

Table B–217

9146

AUE_SetFontPath

Table B–207

9138

AUE_UngrabServer

Table B–201

Events in Audit Class xc

The following table lists lists in alphabetical order the xc class of audit events provided in the Trusted Solaris 8 4/01 release. This class contains audit events about the creation and destruction of X server object.

Table A–28 X - Object Create/Destroy Operations Audit Events (Default)

Audit Event Number and Event 

Where Described 

9176

AUE_AllocColor

Table B–216

9178

AUE_AllocColorCells

9179

AUE_AllocColorPlanes

9177

AUE_AllocNamedColor

9120

AUE_ChangeProperty

Table B–193

9170

AUE_CreateColormap

Table B–215

9185

AUE_CreateCursor

Table B–219

9186

AUE_CreateGlyphCursor

Table B–220

9103

AUE_CreateWindow

Table B–192

9121

AUE_DeleteProperty

Table B–193

9107

AUE_DestroySubwindows

Table B–192

9106

AUE_DestroyWindow

 

9171

AUE_FreeColormap

Table B–217

9180

AUE_FreeColors

Table B–216

9187

AUE_FreeCursor

Table B–221

9152

AUE_FreeGC

Table B–210

9147

AUE_FreePixmap

Table B–222

9197

AUE_KillClient

Table B–226

Events in Audit Class xl

The following table lists in alphabetical order the xl audit events provided in the Trusted Solaris 8 4/01 release.

Table A–29 X - Client Login/Logout Audit Events (Default)

Audit Event Number and Event 

Where Described 

9101

AUE_ClientConnect

Table B–190

9102

AUE_ClientDisConnect

Table B–191

Events in Audit Class xp

The following table lists in alphabetical order the xp audit events provided in the Trusted Solaris 8 4/01 release.

Table A–30 X - Privileged Audit Events (Default)

Audit Event Number and Event 

Where Described 

9148

AUE_ChangeGc

Table B–208

9120

AUE_ChangeProperty

Table B–193

9108

AUE_ChangeSaveSet

Table B–192

9104

AUE_ChangeWindowAttributes

 

9115

AUE_CirculateWindow

 

9114

AUE_ConfigureWindow

 

9172

AUE_CopyColormapAndFree

Table B–217

9149

AUE_CopyGC

Table B–209

9161

AUE_FillPolygon

Table B–213

9199

AUE_ForceScreenSaver

Table B–224

9116

AUE_GetGeometry

Table B–192

9140

AUE_GetMotionEvents

Table B–203

9122

AUE_GetProperty

Table B–193

9105

AUE_GetWindowAttributes

Table B–192

9130

AUE_GrabButton

Table B–196

9135

AUE_GrabKey

Table B–199

9133

AUE_GrabKeyboard

Table B–200

9128

AUE_GrabPointer

Table B–197

9168

AUE_ImageText8

Table B–214

9169

AUE_ImageText16

9173

AUE_InstallColormap

Table B–217

9123

AUE_ListProperties

Table B–193

9184

AUE_LookupColor

Table B–218

9111

AUE_MapSubwindows

Table B–192

9110

AUE_MapWindow

 

9160

AUE_PolyArc

Table B–213

9163

AUE_PolyFillArc

9162

AUE_PolyFillRectangle

9157

AUE_PolyLine

9156

AUE_PolyPoint

9158

AUE_PolySegment

9166

AUE_PolyText8

Table B–214

9167

AUE_PolyText16

9164

AUE_PutImage

9183

AUE_QueryColors

Table B–218

9145

AUE_QueryKeymap

Table B–206

9139

AUE_QueryPointer

Table B–202

9117

AUE_QueryTree

Table B–192

9188

AUE_RecolorCursor

Table B–221

9109

AUE_ReparentWindow

Table B–192

9198

AUE_RotateProperties

Table B–227

9195

AUE_SetAccessControl

Table B–226

9151

AUE_SetClipRectangles

Table B–210

9150

AUE_SetDashes

9193

AUE_SetScreenSaver

Table B–224

9124

AUE_SetSelectionOwner

Table B–195

9181

AUE_StoreColors

Table B–218

9182

AUE_StoreNamedColor

9141

AUE_TranslateCoords

Table B–204

9136

AUE_UngrabKey

Table B–200

9174

AUE_UninstallColormap

Table B–217

9113

AUE_UnmapSubwindows

Table B–192

9112

AUE_UnmapWindow

 

9202

AUE_XExtensions

Table B–229

Events in Audit Class xs

The following table lists in alphabetical order the xs audit events provided in the Trusted Solaris 8 4/01 release.


Note –

These events should be audited for success only, not for failure.


Table A–31 X - Fail Silently Audit Events (Default)

Audit Event Number and Event 

Where Described 

9193

AUE_Bell

Table B–223

9132

AUE_ChangeActivePointerGrab

Table B–198

9190

AUE_ChangeKeyboardControl

Table B–223

9189

AUE_ChangeKeyboardMapping

9192

AUE_ChangePointerControl

9126

AUE_ConvertSelection

Table B–195

9154

AUE_CopyArea

Table B–212

9155

AUE_CopyPlane

 

9119

AUE_GetAtomName

Table B–194

9165

AUE_GetImage

Table B–214

9144

AUE_GetInputFocus

Table B–205

9125

AUE_GetSelectionOwner

Table B–195

9128

AUE_GrabPointer

Table B–197

9118

AUE_InternAtom

Table B–194

9175

AUE_ListInstalledColormap

Table B–217

9159

AUE_PolyRectangle

Table B–213

9127

AUE_SendEvent

Table B–203

9196

AUE_SetCloseDownMode

Table B–225

9143

AUE_SetInputFocus

Table B–205

9201

AUE_SetModifierMapping

Table B–228

9200

AUE_SetPointerMapping

9124

AUE_SetSelectionOwner

Table B–195

9134

AUE_UngrabKeyboard

Table B–199

9129

AUE_UngrabPointer

Table B–197

9131

AUE_UngrabButton

9142

AUE_WarpPointer

Table B–204