Managing Auditing in Oracle® Solaris 11.2

Exit Print View

Updated: July 2014

Customizing What Is Audited

The following task map points to procedures to configure auditing that is specific to your needs.

Table 3-2  Customizing Auditing Task Map
For Instructions
Audit everything that a user does on the system.
Audit one or more users for every command.
Change the audit events that are being recorded and have the change affect existing sessions.
Update a user's preselection mask.
Locate modifications to particular files.
Audit file modifications, then use the auditreduce command to find particular files.
Use less file system space for audit files.
Use ZFS quotas and compression.
Remove audit events from the audit_event file.
Correctly update the audit_event file.