Alternative to audusr command in standard mode


 
Thread Tools Search this Thread
Operating Systems HP-UX Alternative to audusr command in standard mode
# 1  
Old 05-26-2017
HP Alternative to audusr command in standard mode

I need some help in finding which users have the audit setting turned on in the standard mode on a hpux OS 1131 from my application.

I am using audusr from the C code in trusted mode. Need help what to do in standard mode.

Last edited by einsteinBrain; 05-27-2017 at 11:39 AM.. Reason: mention the OS version
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. UNIX for Beginners Questions & Answers

Alternative to cp command

Good Afternoon, I'm backing up a folder from one NAS to another using a unix script using cp. Its a lot of files and takes several days to complete. Most of the files don't change from week to week. Is there a command that would be quicker? Also note, the backup needs to be ready-to-use in... (5 Replies)
Discussion started by: Stellaman1977
5 Replies

2. UNIX for Beginners Questions & Answers

Alternative to join command

Ubuntu, Bash 4.3.48 Hi, I have 2 files and I want to join them (line by line if the start of the lines is the same, like a ID) INPUT FILE 1 (tab delimited) aa_12_12_v_c aaa,asf,afgas,eg bb_12_43_a_d dad,ada,adaf,afa cc_56_75_d_f asd,thh,ert,rtertet INPUT FILE 2 (tab delimited)... (4 Replies)
Discussion started by: echo manolis
4 Replies

3. HP-UX

From a C++ application how to find if a hpux host is in standard mode or trusted mode

is there a way for my C++ application to find out which mode the hpux OS is running in? standard mode or trusted mode. (3 Replies)
Discussion started by: einsteinBrain
3 Replies

4. Shell Programming and Scripting

Maxdepth command not working in AIX.Need alternative solution for this command

Hi All, I am trying to select 30 days older files under current directory ,but not from subdirectory using below command. find <Dir> -type f -mtime + 30 This command selecting all the files from current directory and also from sub directory . I read some documention through internet ,... (1 Reply)
Discussion started by: kommineni
1 Replies

5. AIX

Alternative command for topas

hi, I need alternative command for topas to check cpu %, i tried with ps but their is lot of diffference between the outputs of two commands... Thanks (3 Replies)
Discussion started by: sumanthupar
3 Replies

6. Homework & Coursework Questions

locate command alternative,,

Use and complete the template provided. The entire template must be completed. If you don't, your post may be deleted! Ok, Im back with another small problem. I created a script (the one posted in the last thread). After some help from some members here all is good. The problem is I made it... (4 Replies)
Discussion started by: ozman911
4 Replies

7. Shell Programming and Scripting

Any alternative of sar command

Hi all, I am using linux box ...i dont find the manual entry of sar command through man sar ...it is in unix not in linux although i have to check the cpu utilization and paging...any alternative of sar command.. Thanks Vijay Sahu (1 Reply)
Discussion started by: vijays3
1 Replies

8. UNIX for Dummies Questions & Answers

alternative for head command

Hi friends,I am new to unix and this is really a dummy question.but please help me out. How to simulate head command without using head command??? also tail command too,also more command. it is given as a homework to do....please tell me how to do (2 Replies)
Discussion started by: nikhilneela
2 Replies

9. HP-UX

how to distinguish standard system mode or trust system mode

I think that if the directory /tcb exists, HP-UX is in trusted mode and the passwd data is somewhere in /tcb/files/auth. But that's all I remember. Also I think recent versions of HP-UX can have a /etc/shadow file. (0 Replies)
Discussion started by: Perderabo
0 Replies

10. UNIX for Dummies Questions & Answers

an alternative of sed command..--imp

Hi Is there a better alternative to sed command.. or any command as an alternate to sed. Thanks!! (3 Replies)
Discussion started by: aixjadoo
3 Replies
Login or Register to Ask a Question
audit(5)							File Formats Manual							  audit(5)

NAME
audit - introduction to HP-UX Auditing System DESCRIPTION
The purpose of the auditing system is to record instances of access by subjects to objects and to allow detection of any (repeated) attempts to bypass the protection mechanism and any misuses of privileges, thus acting as a deterrent against system abuses and exposing potential security weaknesses in the system. User and Event Selection The auditing system provides administrators with a mechanism to select users and activities to be audited. On a system that has been converted to trusted mode, users are assigned unique identifiers called by the administrator, which remain unchanged throughout a user's history. See about trusted mode. The command is used to specify those users who are to be audited. On a system that has not been converted to trusted mode, each login session is assigned a unique identifier called The is a string repre- senting information such as user name and login time. It can uniquely identify each login session and the person responsible for the ses- sion. See also setauduser(3) and getauduser(3). The command is used to specify those users who are to be audited. See userdbset(1M) and userdb(4). The associated attribute is called and is described in security(4). The command is used to specify system activities (auditable events) that are to be audited. Auditable events are classified into event categories and profiles for easier configuration. Once an event category or a profile is selected, all system calls and self-auditing events associated with that event category or profile are selected. When the auditing system is installed, a default set of event classi- fication information is provided in file In order to meet site-specific requirements, administrators may also define event categories and profiles in See audit.conf(4) and audevent(1M) for more information. Note that even if an user is not selected for auditing, it is expected that some records may still be generated at the time user starts a session and ends a session. Those are considered as system-wise information that are more in favor of event selection than the user selec- tion. Other programs that do self-auditing may also make arbitrary decision to ignore the user selection though it is not recommended. More information about self-auditing programs can be found later. Starting and Halting the Auditing System The administrator can use the command to start or halt the auditing system, or to get a brief summary of the status of the audit system. Prior to starting the auditing system, also validates the parameters specified, and ensures that the auditing system is in a safe and con- sistent state. See audsys(1M) for more information. Monitoring the Auditing System To ensure that the auditing system operates normally and to detect abnormal behaviors, a privileged program, runs in the background to mon- itor various auditing system parameters. When these parameters take on abnormal (dangerous) values, or when components of the auditing system are accidentally removed, prints warning messages and tries to resolve the problem if possible. See audomon(1M) for more informa- tion. can be spawned by (as part of the start-up process) when the system is booted up if the parameter AUDITING is set to 1 in file It can also be started any time by a privileged user. Viewing of Audited Data The command is used to view audited data recorded in log files. The command merges the log files into a single audit trail in chronologi- cal sequence. The administrator can select viewing criteria provided by the command to limit the search to particular kinds of events which the administrator is interested in investigating. Audit Trails At any time when the auditing system is enabled, at least an audit trail must be present. The trail name and various attributes for the trail can be specified using When the current trail exceeds the specified size, or when the auditing file system is dangerously full, the system automatically switches to another trail with the same base name but a different timestamp extension and begin recording to it. A script can be specified using to perform various operations on the last audit trail after each successful switch. If trail switch is unsuccessful, warning messages are sent to request appropriate administrator action. Self-auditing Programs To reduce the amount of log data and to provide a higher-level recording of some typical system operations, a collection of privileged pro- grams are given capabilities to perform self-auditing. This means that the programs can suspend the currently specified auditing on them- selves and produce a high-level description of the operations they perform. These self-auditing programs are described in the following manpages: at(1), chfn(1), chsh(1), crontab(1), login(1), newgrp(1), passwd(1), audevent(1M), audisp(1M), audsys(1M), audusr(1M), cron(1M), groupadd(1M), groupdel(1M), groupmod(1M), init(1M), lpsched(1M), sam(1M), useradd(1M), userdel(1M), and usermod(1M). Note: Only privileged programs are allowed to do self-auditing. The audit suspension they perform only affects these programs and does not affect any other processes on the system. Most of these commands generate audit data under a single event category. For example, generates the audit data under the event admin. Other commands may generate data under multiple event categories. For example, the command generates data under the events login and admin. For a list of predefined event categories, see audevent(1M). WARNINGS
HP-UX 11i Version 3 is the last release to support trusted systems functionality. The HP-UX Auditing System continues to work without converting to trusted mode. AUTHOR
The auditing system described above was developed by HP. SEE ALSO
audevent(1M), audisp(1M), audsys(1M), audusr(1M), userdbset(1M), audctl(2), audswitch(2), audwrite(2), getaudid(2), getevent(2), setau- did(2), setevent(2), getauduser(3), setauduser(3), audit(4), security(4), userdb(4), audit_memory_usage(5), audit_track_paths(5), diskau- dit_flush_interval(5). audit(5)