Oracle Solaris System Administration (MOSC)

MOSC Banner

What to do with audit files

edited Mar 22, 2013 1:32AM in Oracle Solaris System Administration (MOSC) 3 commentsAnswered
 While I have solaris auditing turned on and configured and happily creating away its bevy of binary snoop files, and I'm perfectly comfortable with auditreduce and praudit for doing the investigation pieces when needed; there still seems to be a pretty big hole when it comes to enterprise level security administration. I would think there would be a tool, preferably oracle supported, for security administrators which would parse these files searching for triggers and alerting on them. Does such a tool exist?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center