What to do with audit files
While I have solaris auditing turned on and configured and happily creating away its bevy of binary snoop files, and I'm perfectly comfortable with auditreduce and praudit for doing the investigation pieces when needed; there still seems to be a pretty big hole when it comes to enterprise level security administration. I would think there would be a tool, preferably oracle supported, for security administrators which would parse these files searching for triggers and alerting on them. Does such a tool exist?
0