The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > OS Specific Forums > SUN Solaris
Google UNIX.COM


SUN Solaris The Solaris Operating System, usually known simply as Solaris, is a free Unix-based operating system introduced by Sun Microsystems .

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
audit in solaris raghavender_sri SUN Solaris 1 03-02-2008 05:56 PM
I need to audit users on a Solaris box PapaPark SUN Solaris 5 03-07-2007 01:17 PM
Sun Solaris Audit Program ghanshyampatel SUN Solaris 4 02-22-2007 07:52 AM
How to turn on Audit trial for Solaris 8 civic2005 SUN Solaris 2 02-22-2007 07:45 AM
Audit in SCO tatiana SCO 1 02-03-2006 08:52 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-20-2007
Registered User
 

Join Date: Nov 2007
Posts: 9
Stumble this Post!
Solaris BSM audit log

I got a lot of this message in my /var/audit log

how can I exclude this message?

header,127,2,invalid event number,fe,hostsol1.com.sg,2007-12-21 00:10:01.001 +08:00,argument,1,0x5,processor ID,argument
,2,0x3,flag,text,P_STATUS,subject,zhang1,root,root,root,root,18228,576129155,291 131094 10.88.95.158,return,failure: Invalid
argument,-1
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 03-02-2008
Registered User
 

Join Date: Feb 2007
Posts: 22
Stumble this Post!
Quote:
Originally Posted by geoffry View Post
I got a lot of this message in my /var/audit log

how can I exclude this message?

header,127,2,invalid event number,fe,hostsol1.com.sg,2007-12-21 00:10:01.001 +08:00,argument,1,0x5,processor ID,argument
,2,0x3,flag,text,P_STATUS,subject,zhang1,root,root,root,root,18228,576129155,291 131094 10.88.95.158,return,failure: Invalid
argument,-1
If you want to exclude a specific audit event from the audit trail you have two choises:
- don't audit the class which the event belongs to
- edit /etc/security/audit_event and remove the event class
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 09:55 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0