Manual page for AUDIT(8)
audit - audit trail maintenance
This program is available with the
software installation option. Refer to
[a manual with the abbreviation INSTALL]
for information on how to install optional software.
command is the general administrator's interface to kernel auditing.
The process audit state for a user can be temporarily or permanently altered.
The audit daemon may be notified to read the contents of the
file and re-initialize the current audit directory to the
first directory listed in the
file, or to open a new audit file
in the current audit directory specified in the
file as last read by the audit daemon.
Auditing may also be terminated/disabled.
Signal audit daemon to close the current audit file and open a new
audit file in the current audit directory.
Signal audit daemon to read audit control file. The audit daemon stores
the information internally.
Signal audit daemon to disable auditing and die.
- -d username
Change the process audit state of all processes owned by
This new process audit state is constructed from the
system and user audit values as specified in the
- -u username audit_event_state
Set the process audit state from
for all current processes owned by
for the format of the system audit value.
The process audit state is one argument.
Enclose the audit event state in quotes,
or do not use
characters in the process audit state specification.
A new login session reconstructs the process audit state
from the audit flags in the
Created by unroff & hp-tools.
© by Hans-Peter Bischof. All Rights Reserved (1997).
Last modified 21/April/97