How do you all handle your /var/adudit logs?
I know about audit -n etc. But what do you use to compress or handle them? This is on a Solaris 9 box. I know about logadm.conf etc, but is there something else or a better way to compress/delete these logs?
In a company I worked some time ago they had a script that:
- closed the actual audit log
- renamed it with the actual date
- compressed it
- moved to another server (nfs or automatic ftp), where security staff could take a look at it, and after some time the logs were moved to TSM and deleted from this server
- restarted the audit process to a new log file
Don't remember the options for audit, but I think man should give you what you need.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.