UNIX Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsUNIX Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Generate data entry and reporting .NET Web apps in minutes, straight from your database. Read our FREE whitepaper “Build Web 2.0 Applications Without Hand-Coding” Download now!
  #1  
Old February 27th, 2004, 04:41 AM
jimmo jimmo is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 21 jimmo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 31 m 21 sec
Reputation Power: 0
Auditing specific processes on Solaris

Hi All!

I am tryinging to figure out how to audit specific processes on Solaris 7 & 8. Or to be more specific, I want a record of when a particular program is started and by whom. BSM is activated and I have looked through the Solaris doc, but I cannot figure out how to audit a specific program/process. Is this possible? If it is in the doc I would appreaciate a kick in the right direction where to look.

Regards,

jimmo

Reply With Quote
  #2  
Old February 27th, 2004, 03:09 PM
fpmurphy fpmurphy is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Location: USA
Posts: 257 fpmurphy User rank is Corporal (100 - 500 Reputation Level)fpmurphy User rank is Corporal (100 - 500 Reputation Level)fpmurphy User rank is Corporal (100 - 500 Reputation Level)fpmurphy User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 23 h 46 sec
Reputation Power: 6
Have a look at the process stop/start class of audit
events i.e. audit class ps.

Reply With Quote
  #3  
Old February 28th, 2004, 03:35 AM
jimmo jimmo is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 21 jimmo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 31 m 21 sec
Reputation Power: 0
Wonderful. I'll take a look. Thanks!

Reply With Quote
  #4  
Old March 22nd, 2004, 07:36 AM
jimmo jimmo is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 21 jimmo User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 31 m 21 sec
Reputation Power: 0
Well, unfortunately I am still not there. I have an application that I want to monitor. That is, I want an audit record each time it is started by any one. So, in the audit_user file, I might have something like this:

other:pc:no
jimmo:pc:no
root:lo,pc:no

Which I interpret it to say that for root, audit login events and process events, also process events for jimmo and all other users. Well, here is where I stop. I can use praudit to look at the current audit log and see that it is logging process events. Including events for the process I am looking for. Unfortunately, I see all of the process events for this user. Some of which I really don't care about. What I really when to know is who starts a particular application and and when without all of the other process events.

Is there anyway of auditing just specific events or do I need to filter them from the audit log?

Regards,

jimmo

Last edited by jimmo : March 22nd, 2004 at 07:44 AM.

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsUNIX Help > Auditing specific processes on Solaris


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway