The audit records are stored in a file called the audit log. The location for the audit log is specified in the seos.ini file. The seaudit utility or CA ControlMinder Endpoint Management can be used to list recorded events in the audit log, filter events by time restrictions or event type, and so on.
Note: For more information about seaudit, see the Reference Guide.
The audit logs are stored locally, but you can use CA ControlMinder to distribute the auditing information by using the log routing facility. Consider archiving old audit logs to tape, to allow you to scan the events later.
By default, the authorization daemon seosd creates the audit logs with root ownership, since the seosd program is executed by the user root. For the same reason, the audit logs are created with read/write permissions granted only to root.
To enable other users to read the audit logs without having to su (substitute user) to root, CA ControlMinder includes two entries in the seos.ini file that specify which group ownership is assigned to the log files.
Suppose the auditors at your site are all members of a group named auditforce. You want these users to be able to browse through the local audit log files. Edit the seos.ini file so that the audit_group token in the [logmgr] section is set to auditforce. CA ControlMinder then gives the auditforce group read permission to your local audit logs. From this point, any local audit logs created at your station have the auditforce group as their owner.
The log routing daemons consult the same token to see who should have access rights to the audit logs that the daemons produce and collect. Note that the audit logs are subject to access control like any other files, and CA ControlMinder rules can keep users from accessing them.
| Copyright © 2013 CA. All rights reserved. |
|