19.4.使用审计跟踪
# praudit /var/audit/AUDITFILEheader,133,10,execve(2),0,Mon Sep 25 15:58:03 2006, + 384 msec
exec arg,finger,doug
path,/usr/bin/finger
attribute,555,root,wheel,90,24918,104944
subject,robert,root,wheel,root,wheel,38439,38032,42086,128.232.9.100
return,success,0
trailer,133# auditreduce -u trhodes /var/audit/AUDITFILE | praudit19.4.1. 使用审计管道进行实时监控
19.4.2. 审计日志文件的轮换和压缩
最后更新于