
April 26th, 2004, 05:52 AM
|
|
Registered User
|
|
Join Date: Feb 2004
Posts: 21
Time spent in forums: 6 h 31 m 21 sec
Reputation Power: 0
|
|
|
newbie Solaris Auditing
Hi All!
I am curious about the site of the audit log. Currently it seems to be growing about 100K per hour. In audit_user, the only entry I have is:
root:lo:no
I interpret this to mean that only login events for root will be logged. So, it seems to be that 100K per hour is a bit much. I also see spurts sometimes. For example, just now, the audit log grew about 300K in about 5 minutes.
Using praudit, I see alot of process events that are being logged. (e.g. fork, exexcv, sepgrp, etc). However, I am at a loss to see where I have enabled this.
Any help is appreciated.
Regards,
jimmo
|