System Administration Commands praudit(1M)
NAME
praudit - print contents of an audit trail file
SYNOPSIS
praudit [-lrsx] [-ddel] [filename]...
DESCRIPTION
praudit reads the listed filenames (or standard input, if no
filename is specified) and interprets the data as audit
trail records as defined in audit.log(4). By default, times,
user and group IDs (UIDs and GIDs, respectively) are con-
verted to their ASCI representation. Record type and event
fields are converted to their ASCI representation. A max-
imum of 100 audit files can be specified on the command
line.
OPTIONS
The following options are supported:
-ddel
Use del as the field delimiter instead of the default
delimiter, which is the comma. If del has special mean-
ing for the shell, it must be quoted. The maximum size
of a delimiter is three characters. The delimiter is not
meaningful and is not used when the -x option is speci-
fied.
-l
Print one line per record.
-r
Print records in their raw form. Times, UIDs, GIDs,
record types, and events are displayed as integers. This
option and the -s option are exclusive. If both are
used, a format usage error message is output.
-s
Print records in their short form. All numeric fields
are converted to ASCI and displayed. The short ASCI
representations for the record type and event fields are
used. This option and the -r option are exclusive. If
both are used, a format usage error message is output.
SunOS 5.11 Last change: 16 Apr 2008 1
System Administration Commands praudit(1M)
-x
Print records in XML form. Tags are included in the out-
put to identify tokens and fields within tokens. Output
begins with a valid XML prolog, which includes identifi-
cation of the DTD which can be used to parse the XML.
FILES
/etc/security/auditevent
Audit event definition and class mappings.
/etc/security/auditclass
Audit class definitions.
/usr/share/lib/xml/dtd
Directory containing the verisioned DTD file referenced
in XML output, for example, adtrecord.dtd.1.
/usr/share/lib/xml/style
Directory containing the versioned XSL file referenced
in XML output, for example, adtrecord.xsl.1.
ATRIBUTES
See attributes(5) for descriptions of the following attri-
butes:
ATRIBUTE TYPE ATRIBUTE VALUE
Availability SUNWcsu
Interface Stability See below
The command stability is evolving. The output format is
unstable.
SEE ALSO
SunOS 5.11 Last change: 16 Apr 2008 2
System Administration Commands praudit(1M)
bsmconv(1M), audit(2), getauditflags(3BSM), audit.log(4),
auditclass(4), auditevent(4), group(4), passwd(4), attri-
butes(5)
See the section on Solaris Auditing in System Administration
Guide: Security Services.
NOTES
This functionality is available only if the Solaris Auditing
feature has been enabled. See bsmconv(1M) for more informa-
tion.
SunOS 5.11 Last change: 16 Apr 2008 3
|