|
|
1.1 ! root 1: .TH AUDFMT 1 01/03/84 ! 2: .SH NAME ! 3: audfmt \- format audit trail log data ! 4: .SH SYNOPSIS ! 5: .B audfmt ! 6: [ ! 7: .B \-o ! 8: outfile ! 9: ] ! 10: [infile] ! 11: .SH DESCRIPTION ! 12: .I Audfmt\^ ! 13: formats raw audit trail data. ! 14: .I Audfmt ! 15: reads the raw audit trail data from either the default ! 16: audit file (/usr/adm/audit) or ! 17: .I infile\^ ! 18: if it is specified. ! 19: .I Audfmt\^ ! 20: writes the formatted data to the standard output or to ! 21: .I outfile\^ ! 22: if the ! 23: .B -o ! 24: option is specified. The format of the output is as follows: ! 25: .PP ! 26: .RS ! 27: .B XY uid date cmd path ! 28: .PP ! 29: .RE ! 30: where X = ! 31: .PP ! 32: .RS ! 33: .B R ! 34: file was opened for reading ! 35: .PP ! 36: .B W ! 37: file was opened for writing ! 38: .PP ! 39: .B L ! 40: file was unlinked(removed) ! 41: .PP ! 42: .B N ! 43: audit status changed from off to on ! 44: .PP ! 45: .B F ! 46: audit status changed from on to off ! 47: .PP ! 48: .B E ! 49: file was executed ! 50: .PP ! 51: .RE ! 52: and Y = ! 53: .PP ! 54: .RS ! 55: .B S ! 56: attempt to access file was successful ! 57: .PP ! 58: .B U ! 59: attempt to access file was not successful ! 60: .RE ! 61: .PP ! 62: .B uid ! 63: - the user-id of the person performing the access ! 64: .PP ! 65: .B date ! 66: - the date and time of the access ! 67: .PP ! 68: .B cmd ! 69: - the command used to perform the access ! 70: .PP ! 71: .B path ! 72: - the pathname of the file accessed ! 73: .PP ! 74: While the audit trail facility is running the active logfile can not be ! 75: formatted. The ! 76: .I auditon\^ ! 77: command may be used to change the current logfile. ! 78: .SH AUTHOR ! 79: Mark Monaghan ! 80: .SH SEE ALSO ! 81: audit(1), audit(2), auditon(1), auditoff(1), audon(2), ckaudit(2).
This archive runs on limited infrastructure. Preserving old code on modern bandwidth. Automated agents are requested to crawl responsibly.