The cmd token records the list of arguments and the list of environment variables that are associated with a command.
The cmd token contains the following fields:
A token ID that identifies this token as a cmd token
A count of the command's arguments
The argument list
The length of the next field
The content of the arguments
A count of the environment variables
The list of environment variables
The length of the next field
The content of the environment variables
The praudit -x command shows the fields of the cmd token. The following is a truncated cmd token. The line is wrapped for display purposes.
<cmd><arge>WINDOWID=6823679</arge> <arge>COLORTERM=gnome-terminal</arge> <arge>...LANG=C</arge>...<arge>HOST=machine1</arge> <arge>LPDEST=printer1</arge>...</cmd> |