does this type of audit make sense?
Hi people:
With Solaris 1X, a lot of people enable auditlogs. Today *nix/*nux server have barely a dozen of humans users who can login on the OS.
My question is this suggested line for audit logs really means. Hey audit lo,ad,ft,ex on everybody not for root?
rolemod -K audit_flags=lo,ad,ft,ex:no root
Am I wrong? If that true; why don't audit root who is the most valuable account or role (if using RBACs)?
Does make sense audit everybody but root?
I really appreciate your thougths about this.