Controlling and Displaying Audit TrailsAudit daemons log audit records sent from audit clients into an audit trail file. If the audit daemon is started without any argument, then the default audit trail file used is dcelocal/var/audit/adm/central_trail. You can also direct the audit trail to another file by using the -t option of the auditd command when starting daemon; the trail argument to the -t option specifies the pathname of the file to which the logs should be written. More: Controlling the Audit Trail Size Changing the Audit Trail File Storage Option
|