Novell LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009 Manual page 378

Hide thumbs Also See for LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009:
Table of Contents

Advertisement

Search by Command Line Name
View records related to a certain command, using the ausearch -c comm_name
command, for example, ausearch -c less for all records related to the less
command.
Search by Executable Name
View records related to a certain executable with the ausearch -x exe com-
mand, for example ausearch -x /usr/bin/less for all records related to
the /usr/bin/less executable.
Search by System Call Name
View records related to a certain system call with the ausearch -sc syscall
command, for example, ausearch -sc open for all records related to the
open system call.
Search by Process ID
View records related to a certain process ID with the ausearch -p pid com-
mand, for example ausearch -p 13368 for all records related to this process
ID.
Search by Event or System Call Success Value
View records containing a certain system call success value with ausearch -sv
success_value, for example, ausearch -sv yes for all successful system
calls.
Search by Filename
View records containing a certain filename with ausearch -f filename,
for example, ausearch -f /foo/bar for all records related to the /foo/
bar file. Using the filename alone would work as well, but using relative paths
would not.
Search by Terminal
View records of events related to a certain terminal only with ausearch -tm
term, for example, ausearch -tm ssh to view all records related to events
on the SSH terminal and ausearch -tm tty to view all events
related to the console.
366
Security Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise desktop 11

Table of Contents