home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!know!hri.com!noc.near.net!news.bbn.com!usc!zaphod.mps.ohio-state.edu!sol.ctr.columbia.edu!ira.uka.de!gmd.de!Germany.EU.net!drsrv1!news
- From: news@drsrv1.hmi.de (News-Operator)
- Newsgroups: comp.unix.ultrix
- Subject: Q: Which events should I 'audit'?
- Keywords: auditd, security, disk space
- Message-ID: <4584@dvwbs6.hmi.de>
- Date: 12 Nov 92 13:26:11 GMT
- Organization: Hahn-Meitner-Institut Berlin GmbH
- Lines: 19
-
- I use 'auditd' to keep control what happens on our machine (Ultrix 4.2).
- Because of the huge amount of data generated by it we have to
- reininitialize the daemon every night. Nevertheless, some 10MB of data
- are on my disks at midnight.
-
- One way of reduction is to select less events in my file 'audit_events'.
- I would like to ask you all what your events file looks like.
-
- Ahh, for security reasons: probably you don't want to tell me your
- security details :-) The question for you is: Do you know which events
- produce more data (-> appear more often) then others but are to be
- considered 'trusted'.
-
- Thanks in advance -Andreas.
- --
- Andreas Schulz-Dieterich Hahn-Meitner-Institut Berlin GmbH,D1
- schulz-dieterich@vax.hmi.dbp.de Glienicker Str. 100
- andi@dvwbs6.hmi.de D-W1000 Berlin 39
- Tel. +49 30 8009-2520 Fax. +49 30 8009-2096 Germany
-