auditstat - display kernel audit statistics
auditstat [-n] [-v]
auditstat [-Z] [-z zone[,...]] [-T d | u] [-i interval [-c count]]
auditstat displays kernel audit statistics. The fields displayed are as follows:
The total number of audit records processed by the userland audit.
This field is obsolete.
The total number of audit records that have been dropped. Records are dropped according to the kernel audit policy. See auditconfig(8), AUDIT_CNT policy for details.
The total number of audit records put on the kernel audit queue.
The total number of audit records that have been constructed (not the number written).
The total number of audit records produced by user processes (as a result of system calls).
The total number of Kbytes of memory currently in use by the kernel audit module.
The total number of non-attributable audit records that have been constructed. These are audit records that are not attributable to any particular user.
The total number of times that the audit queue has blocked waiting to process audit data.
The total number of Kbytes of audit data written to the audit trail.
The total number of times that user processes blocked on the audit queue at the high water mark.
The total number of audit records written. The difference between enq and wrtn is the number of outstanding audit records on the audit queue that have not been written.
Display the statistics a total of count times. If count is equal to zero, statistics are displayed indefinitely. A time interval must be specified.
Display the statistics every interval where interval is the number of seconds to sleep between each collection.
Display the number of kernel audit events currently configured.
Display a time stamp.
Display the version number of the kernel audit module software.
Display statistics for all active zones. This option is only available in the global zone.
Display statistics for the named zones. The named zones must be active. This option is only available in the global zone.
auditstat returns 0 upon success and 1 upon failure.
See attributes(7) for descriptions of the following attributes:
The command is Committed. The output is Not-an-Interface.