Customizing What Is Audited
The following task map points to procedures to configure auditing that is specific to your
needs.
Table 3-2 Customizing Auditing Task Map
|
|
|
Audit everything that a user does on the system.
|
Audit one or more users for every command.
|
|
Change the audit events that are being recorded and have the change affect existing
sessions.
|
Update a user's preselection mask.
|
|
Locate modifications to particular files.
|
Audit file modifications, then use the auditreduce command to find
particular files.
|
|
Use less file system space for audit files.
|
Use ZFS quotas and compression.
|
|
Remove audit events from the audit_event file.
|
Correctly update the audit_event file.
|
|
|