Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

/var/adm/sulog

Status
Not open for further replies.

job357

Technical User
Sep 16, 2002
106
US
How can I configure my system, so that my sulogs will display more in detail. As of now this is all I get:

SU 11/24 03:28 + pts/1

I want to be able to see commands attempted by user(s)

Thanks.
 
Look at 'man sulog'. Solaris 'su' won't log commands being executed by the given user. It only logs the attempt/failure/success of su. If you really want to maintain a trail of commands executed by the user once they have su(d) to another user, you'll have to enable C2 auditing and use the Basic Security Module (BSM) for such.

Look at the script /etc/security/bsmconv. It enables auditing on the system and after reboot auditd will be running. You need to understand what you are enabling before just running the script. Enabling auditing on a system can degrade performance between 5 and 15% - more if you audit too many events. It will allow you to use praudit and audit reduce in order to trace user activities.

If there really is some interest in using BSM, I'll drop a FAQ - just let me know.

Cheers,

Keith
 
Thanks,
I have dual CPU's, enabling BSM should be a problem. It would be nice if you could drop a faq.

I will look around until then :)

Thanks.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top