02-22-2007
Quote:
Originally Posted by ghanshyampatel
Any one has, sun solaris audit program which covers everything one need to check as a security auditor.
I think you need to be a bit more specific about what you mean with "everything". What kind of auditing do you want? Executed commands, files changed, files deleted, incoming network connections, etc.
For more information, see
http://auditanalyzer.com/auditing/solaris/
10 More Discussions You Might Find Interesting
1. Solaris
I got a lot of this message in my /var/audit log
how can I exclude this message?
header,127,2,invalid event number,fe,hostsol1.com.sg,2007-12-21 00:10:01.001 +08:00,argument,1,0x5,processor ID,argument
,2,0x3,flag,text,P_STATUS,subject,zhang1,root,root,root,root,18228,576129155,291 131094... (1 Reply)
Discussion started by: geoffry
1 Replies
2. Solaris
How do I know that audit is enabled in soalris. in AIX 'audit query' command gives me the info whether auditing is on or not.
Raghav (1 Reply)
Discussion started by: raghavender_sri
1 Replies
3. Solaris
can you please share what you use to audit what files are deleted, when files are deleted and who deleted them?
thx (1 Reply)
Discussion started by: melanie_pfefer
1 Replies
4. Programming
Can anyone tell me how to compile a c programs on SunSolaris OS 5.1 Version as gcc and cc are not working
Thanks!!!! (4 Replies)
Discussion started by: shivu
4 Replies
5. Solaris
Hi Friends
I am a Solaries newbie and I am looking out for a software or command or config that can capture all commands run by all users on a server on a daily basis. I believe that this Audit is being done in almost all enterprises and would like to know how the same is done there.
Any... (3 Replies)
Discussion started by: Hari_Ganesh
3 Replies
6. Solaris
Hello
We have recently been through an audit of our solaris servers.
All our solaris servers are running version 10.
We have been told to close down all the services and we have closed what we could by using svcadm disable
We only wish to let ssh and the ftp service to run.
Below is a... (3 Replies)
Discussion started by: sollyshah
3 Replies
7. UNIX for Dummies Questions & Answers
Hello!
I am trying to run a program which has used Xlib for its graphical user interface on Solaris through Common Desktop Environment(CDE). All I get is my three required widows open but all blank.They suppose to show some symbols, pictures ad buttons.In the command terminal the following... (1 Reply)
Discussion started by: asif92
1 Replies
8. Solaris
Dear All,
I have one of my Servers, running Solaris 9. I wanna enable the Audit log enabling, the way I did in Solaris 10 Servers.
After running, the bsmconv script, giving the reboots, modifying all the audit files in /etc/security, the audit is enabled, but the audit file which shall be... (3 Replies)
Discussion started by: sumeet1806
3 Replies
9. Solaris
Linux audits in syslog, any time a user is deleted or added. However, I'm running a Solaris11 VM, and find no such entries. How can I enable auditing for useradd and userdel? Oracle's documentation on managing the auditing service, has been of no assistance. Thanks.
Customizing What Is... (7 Replies)
Discussion started by: Nvizn
7 Replies
10. Solaris
hi,
I enabled bsm modules (/etc/security/bsmconv) and rebooted Solaris 10. But service is going into maintenance state. I rebooted server and I see one error saying "sys/c2audit:audit_kssl() not defined properly". I am not sure, what it is indicating and how it should be fixed. Please suggest, how... (5 Replies)
Discussion started by: solaris_1977
5 Replies
LEARN ABOUT HPUX
audswitch
audswitch(2) System Calls Manual audswitch(2)
NAME
audswitch() - suspend or resume auditing on the current process
SYNOPSIS
DESCRIPTION
suspends or resumes auditing within the current process. This call is restricted to users with the privilege.
One of the following flags must be used for aflag:
Suspend auditing on the current process.
Resume auditing on the current process.
can be used in processes with the privilege to temporarily suspend auditing during intervals where auditing is to be handled by the process
itself. Auditing is suspended by a call to with the parameter and resumed later by a call to with the parameter.
An call to resume auditing serves only to reverse the action of a previous call to suspend auditing. A call to to resume auditing when
auditing is not suspended has no effect.
affects only the current process. For example, cannot suspend auditing for processes from the current process. (Use (see setaudproc(2))
to enable or disable auditing for a process and its children).
Security Restrictions
Some or all of the actions associated with this system call require the privilege. Processes owned by the superuser have this privilege.
Processes owned by other users may have this privilege, depending on system configuration. See privileges(5) for more information about
privileged access on systems that support fine-grained privileges.
RETURN VALUE
Upon successful completion, returns If an error occurs, is returned and the global variable is set to indicate the error.
ERRORS
fails if one of the following is true:
The user does not possess the
privilege.
The input parameter is neither
nor
AUTHOR
was developed by HP.
SEE ALSO
audevent(1M), audusr(1M), setaudproc(2), audit(5), privileges(5).
audswitch(2)