How to enable FreeBSD 4.11 audits service?


 
Thread Tools Search this Thread
Operating Systems BSD How to enable FreeBSD 4.11 audits service?
# 1  
Old 12-28-2011
How to enable FreeBSD 4.11 audits service?

Dear all

My FreeBSD is version 4.11,

I want to enable audit,

Can anyone has a step by step document ?

In FreeBSD.org I see the doc look like need recompile kernel?

Is it really..?

Thanks and happy new years.
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. HP-UX

FTP service Enable/Disable

hi everybody, I can easily enable /disable the FTP service from SAM, how can I do this via command line? using inetd? how? cheers, messi (1 Reply)
Discussion started by: messi777
1 Replies

2. UNIX for Dummies Questions & Answers

Problem tring to enable smtp service

People I'm trying to enable de smtp services of a solaris 10 and i get this sendmail: daemon MTA-v4: problem creating SMTP socket sendmail: NOQUEUE: SYSERR(root): opendaemonsocket: daemon MTA-v4: server SMTP socket wedged: exiting Anyone Knows what is bad? Thank for your time ... (1 Reply)
Discussion started by: enkei17
1 Replies

3. UNIX Desktop Questions & Answers

SAS running audits

I'm not sure if anyone can help here. I don't know much about Unix but will give the information that I can. I am trying to run audits of my data with the command sas audit. When it asks for a batch number I put in the number that I am looking to print. When I do this I am getting the... (1 Reply)
Discussion started by: jld1124
1 Replies

4. Programming

Application crashes in FreeBSD 7.1 while working ok in FreeBSD 6.3

Hello there, My mulithreaded application (which is too large to represent the source code here) is crashing after installing FreeBSD 7.1-RELEASE/amd64. It worked properly on others machines (Dual Cores with 4GB of RAM - FreeBSD 6.2-RELEASE/i386). The current machine has 2x Core 2 Duo... (1 Reply)
Discussion started by: Seenquev
1 Replies

5. Linux

Enable sudo for Win AD users authenticated with Linux samba winbind service

Hi everyone, I wonder if anyone ever came across the idea of unifying AD and Linux user accounts We have a Linux machine with 'samba' 'winbind' service configured to let Windows AD users to logon locally using their AD accounts and passwords. I can use 'su' to get to the local user privilege... (0 Replies)
Discussion started by: will_mike
0 Replies

6. Cybersecurity

Security audits

It appears there is alot of talk about different utilities that will pull data from PACCT files, sulogs, loginlogs, etc and put it in a format that is easy to read from multiple systems. Has anyone used or recommend any of these? I need to keep track of security on multiple systems running Non-Stop... (3 Replies)
Discussion started by: breigner
3 Replies

7. UNIX for Advanced & Expert Users

How do I enable RSA authentication (i've already read the FreeBSD handbook on this...

I followed the directions under 10.10.6, but nothing seems to have happened. When I try logging in, nothing has changed. I still login using my username/password combination. I've already created the keyparis, but why isn't this working? What I'm looking to do is to put the pub keypair... (2 Replies)
Discussion started by: xyyz
2 Replies
Login or Register to Ask a Question
AUDIT(2)						      BSD System Calls Manual							  AUDIT(2)

NAME
audit -- commit BSM audit record to audit log SYNOPSIS
#include <bsm/audit.h> int audit(const char *record, u_int length); DESCRIPTION
The audit() system call submits a completed BSM audit record to the system audit log. The record argument is a pointer to the specific event to be recorded and length is the size in bytes of the data to be written. RETURN VALUES
Upon successful completion, the value 0 is returned; otherwise the value -1 is returned and the global variable errno is set to indicate the error. ERRORS
The audit() system call will fail and the data never written if: [EFAULT] The record argument is beyond the allocated address space of the process. [EINVAL] The token ID is invalid or length is larger than MAXAUDITDATA. [EPERM] The process does not have sufficient permission to complete the operation. SEE ALSO
auditon(2), getaudit(2), getaudit_addr(2), getauid(2), setaudit(2), setaudit_addr(2), setauid(2), libbsm(3) HISTORY
The OpenBSM implementation was created by McAfee Research, the security division of McAfee Inc., under contract to Apple Computer Inc. in 2004. It was subsequently adopted by the TrustedBSD Project as the foundation for the OpenBSM distribution. AUTHORS
This software was created by McAfee Research, the security research division of McAfee, Inc., under contract to Apple Computer Inc. Addi- tional authors include Wayne Salamon, Robert Watson, and SPARTA Inc. The Basic Security Module (BSM) interface to audit records and audit event stream format were defined by Sun Microsystems. This manual page was written by Tom Rhodes <trhodes@FreeBSD.org>. BUGS
The FreeBSD kernel does not fully validate that the argument passed is syntactically valid BSM. Submitting invalid audit records may corrupt the audit log. BSD
April 19, 2005 BSD