Print this page
11842 Want audit events for auditon(A_SETPMASK) and friends
Reviewed by: John Levon <john.levon@joyent.com>
Reviewed by: Andy Fiddaman <andy@omniosce.org>

Split Close
Expand all
Collapse all
          --- old/usr/src/cmd/auditrecord/audit_record_attr.txt
          +++ new/usr/src/cmd/auditrecord/audit_record_attr.txt
↓ open down ↓ 451 lines elided ↑ open up ↑
 452  452  #       trailer,176
 453  453  #       header,176,2,auditon(2) - SQCTRL command,,Mon May 15 09:19:35 2000, + 720003197 msec
 454  454  #       argument,3,0x64,setqctrl:aq_hiwater
 455  455  #       argument,3,0xa,setqctrl:aq_lowater
 456  456  #       argument,3,0x400,setqctrl:aq_bufsz
 457  457  #       argument,3,0x14,setqctrl:aq_delay
 458  458  #       subject,tuser10,tuser10,other,root,other,3969,367,255 197121 tmach1
 459  459  #       return,failure: Not owner,-1
 460  460  #       trailer,176
 461  461  
      462 +label=AUE_AUDITON_SETPMASK
      463 +  format=[arg]1:[arg]2
      464 +    comment=3, "setpmask&colon;pid", process
      465 +    comment=3, "setpmask&colon;as_success", audit ID mask:
      466 +    comment=3, "setpmask&colon;as_failure", audit ID mask
      467 +  syscall=auditon: SETPMASK
      468 +
      469 +label=AUE_AUDITON_SETKAUDIT
      470 +  format=arg1:arg2:arg3:inaddr4:arg5:arg6:arg7
      471 +    comment=1, audit user ID, "auid":
      472 +    comment=1, terminal ID, "port":
      473 +    comment=1, type, "type":
      474 +    comment=1, terminal ID, "ip address":
      475 +    comment=1, preselection mask, "as_success":
      476 +    comment=1, preselection mask, "as_failure":
      477 +    comment=1, audit session ID, "asid"
      478 +  syscall=auditon: SETKAUDIT
      479 +
      480 +label=AUE_AUDITON_GETPINFO
      481 +  format=kernel
      482 +  syscall=auditon: GETPINFO
      483 +
      484 +label=AUE_AUDITON_GETKAUDIT
      485 +  format=kernel
      486 +  syscall=auditon: GETKAUDIT
      487 +
      488 +label=AUE_AUDITON_OTHER
      489 +  format=kernel
      490 +  syscall=auditon: OTHER
      491 +
 462  492  label=AUE_AUDITON_STERMID
 463  493    skip=Not used.
 464  494  
 465  495  label=AUE_AUDITSTAT
 466  496    skip=Not used.
 467  497  
 468  498  label=AUE_AUDITSVC
 469  499    skip=Not used.
 470  500  
 471  501  label=AUE_AUDITSYS
↓ open down ↓ 1945 lines elided ↑ open up ↑
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX