Oracle Solaris System Administration (MOSC)

MOSC Banner

does this type of audit make sense?

edited Jun 13, 2023 5:24PM in Oracle Solaris System Administration (MOSC) 2 commentsAnswered ✓

Hi people:

With Solaris 1X, a lot of people enable auditlogs. Today *nix/*nux server have barely a dozen of humans users who can login on the OS.

My question is this suggested line for audit logs really means. Hey audit lo,ad,ft,ex on everybody not for root?

rolemod -K audit_flags=lo,ad,ft,ex:no root

Am I wrong? If that true; why don't audit root who is the most valuable account or role (if using RBACs)?

Does make sense audit everybody but root?

I really appreciate your thougths about this.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center