9 More Discussions You Might Find Interesting
1. Shell Programming and Scripting
Hello all,
I'm trying to update auditd.cron to force rotate daily and gzip audit.log.1. I will probably then remove anything older that 3 months. The part I don't like about my script right now is the sleep command. It seems that the "/sbin/service auditd rotate" command must use a different... (2 Replies)
Discussion started by: cdlaforc
2 Replies
2. UNIX for Dummies Questions & Answers
I'm running CentOS 5.x and want to disable this daemon as it's crashing my server daily!
I didn't install that and don't know why it's started magically for some reason.
Please enlighten me to the answer to this question, I've read the man pages on this and found something that stops it... (2 Replies)
Discussion started by: HiphopTech
2 Replies
3. Cybersecurity
the events done on the serial console does not get logged. I am using BSM audit.
I have enabled all audit flags. Is there anything that im missing?
Please help!! (2 Replies)
Discussion started by: chinchao
2 Replies
4. Linux
Hi All,
could any one point out any open source test-suites for "File cache" testing and as well as performance test suites for the same. Currently my system is up with Linux/ext4.
Regards
Manish (0 Replies)
Discussion started by: hmanish
0 Replies
5. Linux
Hi all
I saw in Microsoft web site www.SysInternals.com a tool called CoreInfo from able to print out on screen the size of the Data and Instruction caches of your processor, the Locigal to Physical Processor mapping, the number of the CPU sockets. etc..
Do you know if in Linux is available a... (2 Replies)
Discussion started by: manustone
2 Replies
6. UNIX for Dummies Questions & Answers
Hi,
I have the following my logs:
Nov 20 04:02:04 mail-07 kernel: audit: audit_backlog=326 > audit_backlog_limit=320
Nov 20 04:02:04 mail-07 kernel: audit: audit_lost=4272 audit_rate_limit=0 audit_backlog_limit=320
Nov 20 04:02:04 mail-07 kernel: audit: backlog limit exceeded
Nov 20... (0 Replies)
Discussion started by: mojoman
0 Replies
7. Red Hat
Has anyone used, or set up auditd?
I want to use it to audit critical system files.
Will this be hard, how would I start setting this up?
:eek: (2 Replies)
Discussion started by: syndex
2 Replies
8. UNIX for Dummies Questions & Answers
I want to disable the auditd daemon on my unix server. Running this daemon on the server causes to system to crash afer every two month. Could any one let me know step by step how to disable it and is there any implication of doing it? (2 Replies)
Discussion started by: skumar11
2 Replies
9. UNIX for Advanced & Expert Users
hi,
What is the difference between UBC cache and Metadata cache ? where can i find UBC cache Hits and Metadata cache Hits in hp-ux?
Advanced thanx for the help. (2 Replies)
Discussion started by: sushaga
2 Replies
ZOS-REMOTE.CONF(5) System Administration Utilities ZOS-REMOTE.CONF(5)
NAME
zos-remote.conf - the audisp-racf plugin configuration file
DESCRIPTION
zos-remote.conf controls the configuration for the audispd-zos-remote(8) Audit dispatcher plugin. The default location for this file is
/etc/audisp/zos-remote.conf, however, a different file can be specified as the first argument to the audispd-zos-remote plugin. See aud-
ispd-zos-remote(8) and auditd(8). The options available are as follows:
server This is the IBM z/OS ITDS server hostname or IP address
port The port number where ITDS is running on the z/OS server. Default is 389 (ldap port)
user The z/OS RACF user ID which the audispd-zos-remote plugin will use to perform Remote Audit requests. This user needs READ access to
FACILITY Class resource IRR.LDAP.REMOTE.AUDIT (See audispd-zos-remote(8)).
password
The password associated the the z/OS user ID configured above.
timeout
The number in seconds that audispd-zos-remote plugin will wait before giving up in connection attempts and event submissions. The
default value is 15
q_depth
The audispd-zos-remote plugin will queue inputed events to the maximum of q_depth events while trying to submit those remotely. This
can handle burst of events or in case of a slow network connection. However, the audispd-zos-remote plugin will drop events in case
the queue is full. The default queue depth is 64 - Increase this value in case you are experiencing event drop due to full queue
(audispd-zos-remote will log this to syslog).
SEE ALSO
audispd-zos-remote(8)
AUTHOR
Klaus Heinrich Kiwi <klausk@br.ibm.com>
IBM
Oct 2007 ZOS-REMOTE.CONF(5)