The sequence token contains a sequence number. The sequence number is incremented every time an audit record is added to the audit trail. This token is useful for debugging.
The sequence token has two fields:
A token ID that identifies this token as a sequence token
A 32-bit unsigned long field that contains the sequence number
The praudit command shows the field of the sequence token:
sequence,1292 |
The praudit -x command shows the content of the sequence token:
<sequence seq-num="1292"/> |
The sequence token is output only when the seq audit policy option is active.