10 More Discussions You Might Find Interesting
1. UNIX for Beginners Questions & Answers
Hello,
I was asked to modify below script to adapt it to Solaris 11.3. I am not sure if it is ksh or bash, but need your assistance to do it for Solaris 11.3
## Variables
flag="/sysadm/bin/queue_enabler.flg"
set -A maillist unixadm@unixhost.tv
############
##### Remove logs older than... (4 Replies)
Discussion started by: feroccimx
4 Replies
2. SCO
SCO 5.0.7 server on an HP Proliant ML350G5 with E200 raid controller.
The message on the server during boot says this message in several places. "Root Account Disabled, but allowing entry via deamon"
At this point, there are some hardware issues to work through first. One is that we don't... (2 Replies)
Discussion started by: cjdavis618
2 Replies
3. AIX
Hello,
I'm trying to install AIX 7.1 on a machine. Unfortunately I forgot to load volume 2 DVD, but the server works fine. Was wondering, what all the contents will be in volume 2?
And I tried loading it after the complete reboot but the blade is not recognizing the volume2 DVD.
Please let... (6 Replies)
Discussion started by: pjeedu2247
6 Replies
4. Shell Programming and Scripting
Hi Guys,
Server time:-
>date
>Wed Nov 14 11:56:23 EST 2012
I want to convert in to Below Formet :-
20121114.1100
And cretae file base on above data : last 48 Hour
20121114.1000 20121114.1100
20121114.0900 20121114.1000
20121114.0800 20121114.0900
20121114.0700 20121114.0800... (2 Replies)
Discussion started by: asavaliya
2 Replies
5. Red Hat
Hello,
What is the simplest way to install CentOS 6.1 with console base-system only using official LiveDVD image on VirtualBox machine? I'd like to get simplest console with network support like FreeBSD base installation. Then, install services which I need.
The installer jest extracts the... (2 Replies)
Discussion started by: newbie_develope
2 Replies
6. Linux
I want to work with a simulation tool of MENTOR GRAPHICS on LINUX. my pc access Mentor remotely with the ssh command. When I run mentor, i always have this message "X-server backing store disabled; this will lead to graphical redraw problems".
when i run the simulation tool i can't display, i... (0 Replies)
Discussion started by: zouekb
0 Replies
7. Ubuntu
Hi folks,
Ubuntu 7.04 server amd64
apache2-2.2.3
postfix-2.3.8
mysql Ver 14.12
SquirrelMail version 1.4.11
I have a running Mail Server. I need to make it as a file server, in addition, allowing users who have accounts (Linux/shell) on the Mail Server to upload/download their files... (1 Reply)
Discussion started by: satimis
1 Replies
8. AIX
Hi there,
I need to install the IBM C++ Compiler in pSeries AIX DEMOpkg 2005 but I can't find
Ifor_ls
Ifor_ls.html.en_US
Ifor_ls.ipf.en_US
Ifor_ls.compat
Ifor_ls.base
Have you got the experience about that?
Thank you very much.
Thang. (0 Replies)
Discussion started by: pvthang43
0 Replies
9. UNIX for Dummies Questions & Answers
I am brand new to UNIX and have been given the task to remove veritas volume manager 3.5 mirroring and install Disksuite mirror on two Solaris 5.8 servers. Does anyone know where I can find step by step instructions to perform these tasks?
Thanks (1 Reply)
Discussion started by: mg2
1 Replies
10. BSD
Does anyone have any Benchmarks for OS X Server in DB Serving.
in comparison to Linux
How bout Darwin?
And How bout Darwin as a Base for a Server?
How bout Ease of Environment Crossplatforms and Various Implementations?
And Finally how bout Develoment? (1 Reply)
Discussion started by: RedVenim
1 Replies
AUDISP-PRELUDE.CONF:(5) System Administration Utilities AUDISP-PRELUDE.CONF:(5)
NAME
audisp-prelude.conf - the audisp-prelude configuration file
DESCRIPTION
audisp-prelude.conf is the file that controls the configuration of the audit based intrusion detection system. There are 2 general kinds of
configuration option types, enablers and actions. The enablers simply have yes/no as the only valid choices.
The action options currently allow ignore, and idmef as its choices. The ignore option means that the IDS still detects events, but only
logs the detection in response. The idmef option means that the IDS will send an IDMEF alert to the prelude manager upon detection.
The configuration options that are available are as follows:
profile
This is a one word character string that is used to identify the profile name in the prelude reporting tools. The default is auditd.
detect_avc
This an enabler that determines if the IDS should be examining SE Linux AVC events. The default is yes.
avc_action
This is an action that determines what response should be taken whenever a SE Linux AVC is detected. The default is idmef.
detect_login
This is an enabler that determines if the IDS should be examining login events. The default is yes.
login_action
This is an action that determines what response should be taken whenever a login event is detected. The default is idmef.
detect_login_fail_max
This is an enabler that determines if the IDS should be looking for maximum number of failed logins for an account. The default is
yes.
login_fail_max_action
This is an action that determines what response should be taken whenever the maximum number of failed logins for an account is
detected. The default is idmef.
detect_login_session_max
This is an enabler that determines if the IDS should be looking for maximum concurrent sessions limit for an account. The default is
yes.
login_session_max_action
This is an action that determines what response should be taken whenever the maximum concurrent sessions limit for an account is
detected. The default is idmef.
detect_login_location
This is an enabler that determines if the IDS should be looking for logins being attempted from a forbidden location. The default is
yes.
login_location_action
This is an action that determines what response should be taken whenever logins are attempted from a forbidden location. The default
is idmef.
detect_login_time_alerts
This is an enabler that determines if the IDS should be looking for logins attempted during a forbidden time. The default is yes.
login_time_action
This is an action that determines what response should be taken whenever logins are attempted during a forbidden time. The default
is idmef.
detect_abend
This is an enabler that determines if the IDS should be looking for programs terminating for an abnormal reason. The default is yes.
abend_action
This is an action that determines what response should be taken whenever programs terminate for an abnormal reason. The default is
idmef.
detect_promiscuous
This is an enabler that determines if the IDS should be looking for promiscuous sockets being opened. The default is yes.
promiscuous_action
This is an action that determines what response should be taken whenever promiscuous sockets are detected open. The default is
idmef.
detect_mac_status
This is an enabler that determines if the IDS should be detecting changes made to the SE Linux MAC enforcement. The default is yes.
mac_status_action
This is an action that determines what response should be taken whenever changes are made to the SE Linux MAC enforcement. The
default is idmef.
detect_group_auth
This is an enabler that determines if the IDS should be detecting whenever a user fails in changing their default group. The default
is yes.
group_auth_act
This is an action that determines what response should be taken whenever a user fails in changing their default group. The default
is idmef.
detect_watched_acct
This is an enabler that determines if the IDS should be detecting a user attempting to login on an account that is being watched.
The accounts to watch is set by the watched_accounts option. The default is yes.
watched_acct_act
This is an action that determines what response should be taken whenever a user attempts to login on an account that is being
watched. The default is idmef.
watched_accounts
This option is a whitespace and comma separated list of accounts to watch. The accounts may be numeric or alphanumeric. If you want
to include a range of accounts, separate them with a dash but no spaces. For example, to watch logins from bin to lp, use "bin-lp".
Only successful logins logins are recorded.
detect_watched_syscall
This is an enabler that determines if the IDS should be detecting whenever a user runs a command that issues a syscall that is being
watched. The default is yes.
watched_syscall_act
This is an action that determines what response should be taken whenever a user runs a command that issues a syscall that is being
watched. The default is idmef.
detect_watched_file
This is an enabler that determines if the IDS should be detecting whenever a user accesses a file that is being watched. The default
is yes.
watched_file_act
This is an action that determines what response should be taken whenever a user accesses a file that is being watched. The default
is idmef.
detect_watched_exec
This is an enabler that determines if the IDS should be detecting whenever a user executes a program that is being watched. The
default is yes.
watched_exec_act
This is an action that determines what response should be taken whenever a user executes a program that is being watched. The
default is idmef.
detect_watched_mk_exe
This is an enabler that determines if the IDS should be detecting whenever a user creates a file that is executable. The default is
yes.
watched_mk_exe_act
This is an action that determines what response should be taken whenever a user creates a file that is executable. The default is
idmef.
SEE ALSO
audispd(8), audisp-prelude(8), prelude-manager(1).
AUTHOR
Steve Grubb
Red Hat Mar 2008 AUDISP-PRELUDE.CONF:(5)