Unix Technical Forum

audit on remove

This is a discussion on audit on remove within the AIX Operating System forums, part of the Unix Operating Systems category; --> Hi, I would like to monitor deleting of file in specific filesystem. I remove "root = general" from /etc/security/audit/config, ...


Go Back   Unix Technical Forum > Unix Operating Systems > AIX Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-16-2008, 07:31 AM
Kralj
 
Posts: n/a
Default audit on remove

Hi,

I would like to monitor deleting of file in specific filesystem.
I remove "root = general" from /etc/security/audit/config, and
remove everything from /etc/security/audit/objects and add:
/home/user/dir_to_monitor:
w = "FILE_Unlink"
r = "FILE_Unlink"
x = "FILE_Unlink"

I get what I want, but log is full of other record ( FS_Chdir,
FS_Mkdir, CRON_Start, ... ) for other directories.
Is there some default or minimal set of records that audit write?

I need to have minimum number of records because this is directory
with large number of files, and log will be huge.

Regards
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 07:31 AM
Kralj
 
Posts: n/a
Default Re: audit on remove

On Jan 14, 10:34 am, Kralj <tomis...@gmail.com> wrote:
more info found:
I removed everything from "classes:" and "users:" in /etc/security/
audit/config, and get rid off all extra lines
from audit log, but I loose info about file name that was deleted.

So I need config that have all possible info for targeted directory,
but none for all else.

Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 03:15 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com