Audit File Tools

You can manage audit files from the Service Processor, using a tool for viewing audit files. Refer to the viewaudit(8) man page for details on this tool.

XSCF Shell Procedures for Auditing

This section describes these tasks:

To Enable or Disable Writing of Audit Records to the Audit Trail

To Configure an Auditing Policy

To Display Whether Auditing is Enabled Or Disabled

To Display Current Auditing Policy, Classes, or Events

To Enable or Disable Writing of Audit Records to the Audit Trail

1.Log in to the XSCF console with auditadm privileges.

2.Type the setaudit command:

XSCF> setaudit enabledisable

where enable enables writing of audit records, and disable disables writing of audit records.

To Configure an Auditing Policy

1.Log in to the XSCF console with auditadm privileges.

2.Type the setaudit command:

XSCF> setaudit [-p countsuspend] [-m mailaddr] [-a users= enabledisabledefault] [-c classes={enabledisable}] [-e events= enabledisable] [-g {enabledisable}] [-t percents]

Refer to the setaudit(8) man page for details on option information.

68 SPARC Enterprise Mx000 Servers Administration Guide • November 2007