aud_audit_events(5sec)Auditable events for the audit services Description Code is in place for auditing audit service-significant events. Among these events are
Administrative operations
Filter operations Event class definitions, together with filters, control the auditing execution at these code points. Filters can be updated dynamically. Filter files are maintained by a per-host audit daemon, and are shared among all the audit clients on the same host. The dcecp command interface program is used to maintain the filters. (See the dcecp reference page.) The dcecp command is executable by all users and system administrators. The control on who is allowed to modify filters is done through the audit daemons ACL, which maintains the filters. The Audit Service RPC interfaces include audit_control and audit_filter operations. Administrative Operations The dce_audit_admin_modify and dce_audit_admin_query event classes lump together the administrative operations that are performed on the audit daemon. The dce_audit_admin_modify event class has the following events that modify the operation of the audit daemon: EVT_MODIFY_STATE - Enables or disables the audit daemon for logging. EVT_MODIFY_SSTRATEGY - Modifies storage strategy. This can be any of the following: Save - If the trail is full, back it up and rename it with a timestamp, then write on the original trail again. Wrap - If the trail is full, go back to the beginning of the file, overwriting previously written records. EVT_REWIND - Rewinds the audit daemons central trail file. EVT_STOP - Stops the audit daemon. Audit Code Points The following are the audit code points in the Audit Service interfaces, with their event types, event classes, and any event-specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information The dce_audit_admin_query event class has two events: EVT_SHOW_SSTRATEGY - Shows the storage strategy. EVT_SHOW_STATE - Shows the state of the audit daemon. Following are the details of this event class:
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information Filter Operations The dce_audit_filter_modify and dce_audit_filter_query event classes are the filter operations that the audit daemon handles. The dce_audit_filter_modify event class has the following events: EVT_ADD_FILTER - Adds a filter. EVT_DELETE_FILTER - Removes all guides for a specific subject. EVT_REMOVE_FILTER - Removes a specific guide for a specific subject. Following are the details of this event class:
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes)
Event-Specific Information The dce_audit_filter_query contains two events: EVT_LIST_FILTER - Lists all subjects that have filters. EVT_SHOW_FILTER - Shows all filters for a specific principal. Following are the details of this event class.
Event Type (Event Number, Event Classes)
Event-Specific Information
Event Type (Event Number, Event Classes) Event-Specific Information
aud_c_evt_info_long_int esl_type Related Information Command: dcecp(8dce) Files: event_class(5sec)
|