Auditing Solaris 10 branded zones
Hi,
I'm running Solaris 11.1 SRU 8.5, and have been trying to use the auditing to audit Solaris 10 branded zones. However, no matter what flags I set, it is logging almost everything.
I am using the audit_syslog plugin with p_flags=lo, and I'm getting open(2) and ioctl etc.
# auditconfig -getplugin
Plugin: audit_binfile (inactive)
Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1
Plugin: audit_syslog (active)
Attributes: p_flags=lo
Plugin: audit_remote (inactive)
Attributes: p_hosts=;p_retries=3;p_timeout=5
David
0