home *** CD-ROM | disk | FTP | other *** search
-
-
-
- ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM)))) ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM))))
-
-
-
- NNNNAAAAMMMMEEEE
- sat_select - preselect events for the system audit trail to gather
-
- SSSSYYYYNNNNOOOOPPPPSSSSIIIISSSS
- ssssaaaatttt____sssseeeelllleeeecccctttt [ ----hhhh ] [ iiiiddddttttyyyyppppeeee ] [ ----oooouuuutttt ] [ ----cccclllleeeeaaaarrrraaaallllllll | ----oooouuuutttt |
- ----oooonnnn | ----ooooffffffff (all | event) ] [ ----ccccooooppppyyyy id ]
-
- ssssaaaatttt____sssseeeelllleeeecccctttt [ ffffiiiilllleeeettttyyyyppppeeee ] filename
-
- DDDDEEEESSSSCCCCRRRRIIIIPPPPTTTTIIIIOOOONNNN
- _s_a_t__s_e_l_e_c_t directs the system audit trail to collect records of a
- particular _i_d_t_y_p_e describing certain events and to ignore records
- describing certain other events. Note that if no _i_d_t_y_p_e is specified,
- then the events will be default to global event mask. _s_a_t__s_e_l_e_c_t with no
- arguments lists the audit events currently being collected.
-
- The effect of multiple executions of _s_a_t__s_e_l_e_c_t is cumulative.
-
- The auditable event types are described in the _I_R_I_X _A_d_m_i_n: _B_a_c_k_u_p,
- _S_e_c_u_r_i_t_y, _a_n_d _A_c_c_o_u_n_t_i_n_g. For a brief, online description, see the
- comments in /_u_s_r/_i_n_c_l_u_d_e/_s_y_s/_s_a_t._h.
-
- See _a_u_d_i_t(1M) or the _I_R_I_X _A_d_m_i_n: _B_a_c_k_u_p, _S_e_c_u_r_i_t_y, _a_n_d _A_c_c_o_u_n_t_i_n_g guide
- for more information on configuring the audit subsystem.
-
- If the audit daemon, _s_a_t_d(1M), isn't running, _s_a_t__s_e_l_e_c_t does not select
- any audit events for auditing. This is to prevent inadvertently halting
- the system, which can happen if an audit daemon is not running to remove
- events from the queue.
-
- OOOOPPPPTTTTIIIIOOOONNNNSSSS
- ----hhhh Help is provided. The names of all possible audit _e_v_e_n_t_s
- are displayed.
-
- iiiiddddttttyyyyppppeeee Is one of the followings:
- ----ssssgggg||||----oooogggg _g_i_d|_n_a_m_e subject|object group
- ----ssssuuuu||||----oooouuuu _u_i_d|_n_a_m_e subject|object user id
- ----ssssmmmm||||----oooommmm _m_a_c__l_a_b_e_l subject|object mac label
- No iiiiddddttttyyyyppppeeee defaults to global event mask.
-
- ----oooouuuutttt Print the names of all active audit _e_v_e_n_t_s for iiiiddddttttyyyyppppeeee. The
- event names are displayed in the same format that _s_a_t__s_e_l_e_c_t
- uses for its command line arguments.
-
- ----oooonnnn _a_l_l|_e_v_e_n_t
- Select the auditing _e_v_e_n_t_s for a particular iiiiddddttttyyyyppppeeee. The
- format of the event string is defined in the
- _s_a_t__e_v_e_n_t_t_o_s_t_r(3) reference page. If aaaallllllll is given as the
- event string, all event types are selected.
-
-
-
-
-
-
- PPPPaaaaggggeeee 1111
-
-
-
-
-
-
- ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM)))) ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM))))
-
-
-
- ----ooooffffffff _a_l_l|_e_v_e_n_t
- Ignore records containing the specified audit _e_v_e_n_t of a
- certain iiiiddddttttyyyyppppeeee. The format of the event string is defined in
- the _s_a_t__e_v_e_n_t_t_o_s_t_r(3) reference page. If aaaallllllll is given as
- the event string, all event types are ignored.
-
- ----ccccooooppppyyyy _i_d Copy the event mask from _i_d to iiiiddddttttyyyyppppeeee.
-
- ----cccclllleeeeaaaarrrraaaallllllll Clears all active auditing event masks (global and id
- specific).
-
- ffffiiiilllleeeettttyyyyppppeeee _f_i_l_e_n_a_m_e
- Set events from _f_i_l_e_n_a_m_e for the ffffiiiilllleeeettttyyyyppppeeee:
- ----FFFF _g_l_o_b_a_l _e_v_e_n_t_s
- ----SSSSGGGG _s_u_b_j_e_c_t _g_i_d _e_v_e_n_t_s
- ----SSSSMMMM _s_u_b_j_e_c_t _l_a_b_e_l _e_v_e_n_t_s
- ----SSSSUUUU _s_u_b_j_e_c_t _u_s_e_r _e_v_e_n_t_s
- ----OOOOGGGG _o_b_j_e_c_t _g_i_d _e_v_e_n_t_s
- ----OOOOMMMM _o_b_j_e_c_t _l_a_b_e_l _e_v_e_n_t_s
- ----OOOOUUUU _o_b_j_e_c_t _u_s_e_r _e_v_e_n_t_s
- The file format for all except the global event file will
- be:
- <<<<iiiidddd>>>> [<<<<iiiidddd>>>>...]: -{----oooonnnn|----ooooffffffff} event ...
- The global event file will remain the same with only the
- events lists. A special event case of aaaallllllll will also be
- accepted in all files, ie. -F global events
-
- FFFFIIIILLLLEEEESSSS
- /etc/init.d/audit system audit startup script
- /etc/config/audit configuration file, oooonnnn if auditing is enabled
- /etc/config/sat_select.options
- optional file for site-dependent _s_a_t__s_e_l_e_c_t options
-
- EEEEXXXXAAAAMMMMPPPPLLLLEEEESSSS
- To collect records describing all System V IPC events (creation, change,
- access, or removal of semaphores, message queues, and shared memory
- segments), in addition to whatever events were previously selected for
- collection, give this command:
-
- _ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt _----_oooo_nnnn _ssss_aaaa_tttt______ssss_vvvv_iiii_pppp_cccc______cccc_rrrr_eeee_aaaa_tttt_eeee _----_oooo_nnnn _ssss_aaaa_tttt______ssss_vvvv_iiii_pppp_cccc______cccc_hhhh_aaaa_nnnn_gggg_eeee _\\\\
- _----_oooo_nnnn _ssss_aaaa_tttt______ssss_vvvv_iiii_pppp_cccc______aaaa_cccc_cccc_eeee_ssss_ssss _----_oooo_nnnn _ssss_aaaa_tttt______ssss_vvvv_iiii_pppp_cccc______rrrr_eeee_mmmm_oooo_vvvv_eeee
-
-
- To ignore records describing all events, regardless of what may have been
- previously selected, but to collect records initiated by trusted
- administrative programs such as _l_o_g_i_n and _s_u, give this command:
-
- _ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt _----_oooo_ffff_ffff _aaaa_llll_llll _----_oooo_nnnn _ssss_aaaa_tttt______aaaa_eeee______aaaa_uuuu_dddd_iiii_tttt _----_oooo_nnnn _ssss_aaaa_tttt______aaaa_eeee______iiii_dddd_eeee_nnnn_tttt_iiii_tttt_yyyy _\\\\
- _----_oooo_nnnn _ssss_aaaa_tttt______aaaa_eeee______cccc_uuuu_ssss_tttt_oooo_mmmm
-
-
-
-
-
-
- PPPPaaaaggggeeee 2222
-
-
-
-
-
-
- ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM)))) ssssaaaatttt____sssseeeelllleeeecccctttt((((1111MMMM))))
-
-
-
- To save the current audit state in a file that _s_a_t__s_e_l_e_c_t can read:
-
- _ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt _----_oooo_uuuu_tttt _>>>> _////_eeee_tttt_cccc_////_cccc_oooo_nnnn_ffff_iiii_gggg_////_ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt_...._oooo_pppp_tttt_iiii_oooo_nnnn_ssss
-
-
- To restore the audit state from a previously saved file:
-
- _ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt _````_cccc_aaaa_tttt _////_eeee_tttt_cccc_////_cccc_oooo_nnnn_ffff_iiii_gggg_////_ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt_...._oooo_pppp_tttt_iiii_oooo_nnnn_ssss_````
-
-
- To read the subject user options from the configuration file:
-
- _ssss_aaaa_tttt______ssss_eeee_llll_eeee_cccc_tttt _----_SSSS_UUUU _gggg_uuuu_eeee_ssss_tttt _f_i_l_e_n_a_m_e
-
- SSSSEEEEEEEE AAAALLLLSSSSOOOO
- sat_interpret(1M), sat_reduce(1M), sat_summarize(1M), satd(1M),
- satctl(2), sat_eventtostr(3).
-
- _I_R_I_X _A_d_m_i_n: _B_a_c_k_u_p, _S_e_c_u_r_i_t_y, _a_n_d _A_c_c_o_u_n_t_i_n_g
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- PPPPaaaaggggeeee 3333
-
-
-
-