HP UX Auditing System Extensions manual

Page 23

The inetd daemon honors the AUDIT_FLAG only for the user under whom the service is run when inetd is started with the –aoption. Self-audit login and logoff events are generated regardless of the inetd –aoption and whether the user is enabled or disabled for auditing. Most inetd services run as user root and disabling auditing for root is not recommended, as this results in no system call auditing of users logged in as root.

After upgrading AuditExt, starting Audit with audsys –nreturns the failed to match audit trail version; specify different audit trail error.

The version of the audit trail for the upgraded product is newer than the previously installed product. You must disable auditing (audsys –f) before upgrading the AudReport product. To proceed after receiving this error, disable auditing and then enable it to start creating an audit trail with the latest version. The new version can include more audit data for each event, for example, the IP address of the origin of the event, the command name of the event, and the audit session ID.

Note:

Both audisp and auditdp are capable of handling both versions of the audit trails. Therefore, you do not need to know about the internal format of raw audit data.

If a system crash or reboot with the reboot -ncommand occurs when the audit trail is being written, the audit trail might be corrupted.

Remove the corrupted audit trail and start the audit subsystem.

23

Image 23
Contents HP-UX 11i v2 and 11i v3 Security Configuring and Managing the Auditing SystemIntroduction AudienceArchitecture CommandsAuditing system overview Files System callsDaemons Audit events Audit tagsAudit trail System call audit records Version recordsSystem call table records PID identification recordsSelf-auditing programs Audit tunable parameters HP-UX 11i v3 onlyAudit aware Page Newgrp1 modaccess Setfilexsec1M modaccess Could not lock file Remote user Usernameunspecified Local System Executing login pid = pid. ipcopenNetworking service = ftp Audit unawareAudit Filtering Auditing system extensions HP-UX 11i v3 onlyDynamically Linked Kernel Modules Audit Reporting HP-UX Auditing System AdministrationInstallation Userdbset command. See userdbset1M and userdb4 ConfigurationConfiguring users for audit Configuring audit settings to be preserved across reboots Configuring events for auditConfiguring audit filtering Role, operation, object Configuring rolesDisabling auditing Reads the /etc/rc.config.d/auditing fileManagement Enabling auditingBest practices Writing a Dpms service moduleService Provider Interfaces SPIs Dpms service module implementationAudit generation and capture Audit policyAudit log analysis Audit retention and storageOpt/audit/AudReport/bin TroubleshootingAudit log configuration, security, and protection Page Audwrite2 GlossaryPage Send comments to HP For more information