09-29-2011
AIX auditing
can some give some tips, most common security issues or and kind of advice about auditing aix system?
regards
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
Hi all,
Have been asked to learn up on providing Sytem Auditing on two SCO boxes.
Where should I start and what pointers can anyone provide.
Whilst I'm learning to look after these two SCO boxes, I'm also to eventually look after three Compaq DS20E True64 Unix boxes also in the near future. (2 Replies)
Discussion started by: Cameron
2 Replies
2. AIX
Hi,
What's the best way to turn on the auditing in AIX 4.3? I'm in an environment where root password are shared with many users.
Can sudoers member be audited properly?
Thanks (1 Reply)
Discussion started by: itik
1 Replies
3. AIX
can someone help me find out the impact of enabling audting on the entire root filesystem. does it have a major hit on the overall performance of the system
Thanks so much (0 Replies)
Discussion started by: iam
0 Replies
4. UNIX for Advanced & Expert Users
:)I need a little help. I have sent all of our logs to our log server, but I can't send the audit logs that are in /var/log/audit.log. Can someone give me some type of idea to transfer these logs.
Thank You (2 Replies)
Discussion started by: aojmoj
2 Replies
5. AIX
I have a question relating with AIX auditing Question is can we set Auditing on a particular file in AIX for a particular application only?
Let say I have a file name "info.jar" and I have three application named APP1, APP2 & APP3 which are accessing that file so I want to know that which... (0 Replies)
Discussion started by: m_raheelahmed
0 Replies
6. AIX
i have sucessfully enable the auditing on AIX with adding som onjects.
but when i go for
auditpr -v < /audit/trail
vlets say i reset audit at last dat 5 pm
auditpr -v < /audit/trail
will show up to last day 5 pm.
i have to reset audit every time to check latest logs.
please... (3 Replies)
Discussion started by: prashantjain07
3 Replies
7. AIX
Hi All,
i've a problem on a AIX server with audit config...
when i start the audit i receive this error:
root@****:/etc/security/audit > /usr/sbin/audit start
Audit start cleanup: The system call does not exist on this system.
** failed setting kernel audit objects
I don't understand... (0 Replies)
Discussion started by: Zio Bill
0 Replies
8. AIX
In our customer place somebody removed and PV from the server. I want the information like which user removed this PV.
Is there any way to get PV removal information.
When did the PV removed from the server ?
Whether AIX auding will help ?
Where i can get these information ?
Thank... (2 Replies)
Discussion started by: sunnybee
2 Replies
9. AIX
I am trying to find out the information of my local desktop when i use putty to login to an AIX server.
This is what I do:
1. login to my PC
2. take a putty session to an AIX server
Can i get information of my local desktop from the AIX server ? Is there a command available ?
Thanks (8 Replies)
Discussion started by: Nagesh_1985
8 Replies
10. AIX
Hi All
I need your help to configure Aix to send logs to Qradar, I did all the methods that mentioned in IBM website and no use, Plz Help,,
The Logs should I receive from Aix and display in Qradar is (create user delete user changing in privileges....etc )
my skype account
khaled_ly84
... (4 Replies)
Discussion started by: khaled_ly84
4 Replies
LEARN ABOUT MOJAVE
madvise
MADVISE(2) BSD System Calls Manual MADVISE(2)
NAME
madvise, posix_madvise -- give advice about use of memory
SYNOPSIS
#include <sys/mman.h>
int
madvise(void *addr, size_t len, int advice);
int
posix_madvise(void *addr, size_t len, int advice);
DESCRIPTION
The madvise() system call allows a process that has knowledge of its memory behavior to describe it to the system. The advice passed in may
be used by the system to alter its virtual memory paging strategy. This advice may improve application and system performance. The behavior
specified in advice can only be one of the following values:
MADV_NORMAL Indicates that the application has no advice to give on its behavior in the specified address range. This is the system
default behavior. This is used with madvise() system call.
POSIX_MADV_NORMAL
Same as MADV_NORMAL but used with posix_madvise() system call.
MADV_SEQUENTIAL Indicates that the application expects to access this address range in a sequential manner. This is used with madvise()
system call.
POSIX_MADV_SEQUENTIAL
Same as MADV_SEQUENTIAL but used with posix_madvise() system call.
MADV_RANDOM Indicates that the application expects to access this address range in a random manner. This is used with madvise() system
call.
POSIX_MADV_RANDOM
Same as MADV_RANDOM but used with posix_madvise() system call.
MADV_WILLNEED Indicates that the application expects to access this address range soon. This is used with madvise() system call.
POSIX_MADV_WILLNEED
Same as MADV_WILLNEED but used with posix_madvise() system call.
MADV_DONTNEED Indicates that the application is not expecting to access this address range soon. This is used with madvise() system call.
POSIX_MADV_DONTNEED
Same as MADV_DONTNEED but used with posix_madvise() system call.
MADV_FREE Indicates that the application will not need the information contained in this address range, so the pages may be reused
right away. The address range will remain valid. This is used with madvise() system call.
MADV_ZERO_WIRED_PAGES
Indicates that the application would like the wired pages in this address range to be zeroed out if the address range is
deallocated without first unwiring the pages (i.e. a munmap(2) without a preceding munlock(2) or the application quits).
This is used with madvise() system call.
The posix_madvise() behaves same as madvise() except that it uses values with POSIX_ prefix for the advice system call argument.
RETURN VALUES
Upon successful completion, a value of 0 is returned. Otherwise, a value of -1 is returned and errno is set to indicate the error.
ERRORS
madvise() fails if one or more of the following are true:
[EINVAL] The value of advice is incorrect.
[EINVAL] The address range includes unallocated regions.
[ENOMEM] The virtual address range specified by the addr and len are outside the range allowed for the address space.
LEGACY SYNOPSIS
#include <sys/types.h>
#include <sys/mman.h>
int
madvise(caddr_t addr, size_t len, int advice);
int
posix_madvise(caddr_t addr, size_t len, int advice);
The include file <sys/types.h> is necessary. The type of addr has changed.
SEE ALSO
mincore(2), minherit(2), mprotect(2), msync(2), munmap(2), compat(5)
HISTORY
The madvise function first appeared in 4.4BSD. The posix_madvise function is part of IEEE 1003.1-2001 and was first implemented in Mac OS X
10.2.
BSD
June 9, 1993 BSD