Audevent(1M): Audevent - HP B2355-92068 Administration Manual

System administration commands
Table of Contents

Advertisement

audevent(1M)
NAME
audevent - change or display event or system call audit status
SYNOPSIS
audevent
a
audevent
DESCRIPTION
audevent
to specify names associated with certain self-auditing commands; syscall is used to select related system
calls.
If neither
-P
displayed.
If the
-E
option is supplied, it is redundant to specify events with the
and
-S
-s
tem calls associated with the selected events are selected.
audevent
when called by a user currently being audited (see audusr(1M)).
If
is specified, a list of valid events and their associated system calls (if any) are displayed. This option
-l
may be helpful when deciding which
Note: The set of audited system calls and corresponding audit events varies frequently as HP-UX
evolves. The system call name referred to by the auditing system usually matches the real system call
name, but with a few exceptions. Some important known exceptions are provided in System Call
Name Mapping Execptions.
Only the super-user can change or display audit status.
Options
audevent
-P
-p
-F
-f
-E
-e
event
-S
syscall
-s
-l
The following is a list of the valid event types or categories:
create
delete
readdac
moddac
modaccess
open
close
process
72
Hewlett-Packard Company
[
-P
-p
] [
-F
-f
] [
-E
] [ [
-e
[
]
-l
changes or displays the auditing status of the given events or system calls. The event is used
,
,
, nor
is specified, the current status of the selected events or system calls is
-p
-F
-f
options. If no event is specified, all events are selected. If no system call is specified, all sys-
takes effect immediately. However, the events and system calls specified are audited only
-e
recognizes the following options and command-line arguments:
Audit successful events or system calls.
Do not audit successful events or system calls.
Audit failed events or system calls.
Do not audit failed events or system calls.
Select all events for change or display.
Select event for change or display.
Select all system calls for change or display.
Select syscall for change or display.
Display a list of valid events and their associated system calls. This option should not
be used with any other options.
Object creation. For example, file creation, directory creation, and other object crea-
tion.
Object deletion. For example, file deletion, directory deletion, and other object dele-
tion.
Discretionary access control (DAC) information reading events.
DAC modification events.
Non-DAC modification events.
Object opening. For example, file open and other object open.
Object closing. For example, file close and other object close.
Process operations.
event ] ... ] [
-S
] [ [
-s
syscall ] ... ]
or
-s
options to use.
− 1 −
HP-UX 11i Version 2: December 2007 Update
audevent(1M)
-e
option. This also applies to the

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hp-ux 11i

Table of Contents