Oracle Solaris System Administration (MOSC)

MOSC Banner

Solaris 10- Audit by BSM works well with commands arguments - But Syslog does not records these argu

edited May 3, 2016 5:07AM in Oracle Solaris System Administration (MOSC) 7 commentsAnswered
Hi all,

I've enabled the BSM audit module on Solaris 10, with the syslog plugin.

I enabled the following class  lo,ex,fw,fc,fd, and also enabled the arguments (/usr/sbin/auditconfig -setpolicy +argv).

I can see in /var/audit/* all the command lines with their arguments. So the auditd works as expected : It audits the commands with their arguments.

The thing is that the syslog only records the commands .... and not the arguments !

To summarize: I can see with 'praudit $myfikle' alld the commands with their arguments, but in the resulting syslog output file (out.txt), I can only see commands (Arguments are missing).

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center