Previous Topic: How to Perform System Maintenance

Next Topic: The System Auditor


Audit Logs

The audit records are stored in a file called the audit log. The location for the audit log is specified in the seos.ini file. The seaudit utility or CA Access Control Endpoint Management can be used to list recorded events in the audit log, filter events by time restrictions or event type, and so on.

Note: For more information about seaudit, see the Reference Guide.

The audit logs are stored locally, but you can use CA Access Control to distribute the auditing information by using the log routing facility. Consider archiving old audit logs to tape, to allow you to scan the events later.

By default, the authorization daemon seosd creates the audit logs with root ownership, since the seosd program is executed by the user root. For the same reason, the audit logs are created with read/write permissions granted only to root.

To enable other users to read the audit logs without having to su (substitute user) to root, CA Access Control includes two entries in the seos.ini file that specify which group ownership is assigned to the log files.