Managing Auditing in Oracle® Solaris 11.4

Updated: February 2019

New Feature – Refreshing the auditset SMF Service After Changing Event-Class Mappings

When you make changes to the /etc/security/audit_event or /etc/security/audit_class configuration files for the audit service, you must refresh the svc:/system/auditset:default service. Administrators who are assigned the Audit Configuration rights profile and the Service Configuration rights profile first configure auditing then refresh the service as follows:

$ pfbash ; auditconfig -conf
$ svcadm refresh auditset:default