Table 2-4 Attribute values for enabling or disabling audit logging (continued)

 

Value of the

 

 

nsslapd-auditlog-logging-enabled

 

Value of the nsslapd-auditlog Attribute

Attribute

Resulting logging state

 

 

 

empty string

off

Disabled

 

 

 

filename

off

Disabled

 

 

 

2.3.1.20 nsslapd-auditlog-list

Provides a list of audit log files.

Parameter

Description

Entry DN

cn=config

 

 

Valid Values

 

 

 

Default Value

None

 

 

Syntax

DirectoryString

 

 

Example

nsslapd-auditlog-list: auditlog2,auditlog3

 

 

2.3.1.21nsslapd-auditlog-logexpirationtime (Audit log expiration time)

This attribute sets the maximum age that a log file is allowed to be before it is deleted. This attribute supplies only the number of units. The units (day, week, month, and so forth) are given by the nsslapd-auditlog-logexpirationtimeunit attribute.

Parameter

Description

EntryDN

cn=config

 

 

ValidRange

-1 to the maximum 32-bit integer value (2147483647)

 

A value of -1 or 0 means that the log never expires.

 

 

DefaultValue

-1

 

 

Syntax

Integer

 

 

Example

nsslapd-auditlog-logexpirationtime: 1

 

 

2.3.1.22 nsslapd-auditlog-logexpirationtimeunit (Audit log expiration time unit)

This attribute sets the units for the nsslapd-auditlog-logexpirationtimeattribute. If the unit is unknown by the server, then the log never expires.

Parameter

Description

Entry DN

cn=config

 

 

Valid Values

month week day

 

 

Default Value

week

 

 

Syntax

DirectoryString

 

 

Example

nsslapd-auditlog-logexpirationtimeunit: day

 

 

2.3 Core server configuration attributes reference

31