
B-10 SPARC Enterprise Mx000 Servers XSCF User’s Guide • December 2010
■ IPL message (Message)
B.5 Audit Log
This section explains how to reference the audit logs by using the viewaudit(8) command.
For details of each log option, audit class, and audit event of viewaudit(8), see the XSCF
Reference Manual or the main page. See
TABLE 8-3 for the size and generation number of
each log.
Using the viewaudit(8) Command to Confirm the Audit Trail
● Perform the viewaudit(8) command on the XSCF Shell.
In the example above, By default records are displayed in text format, one token per line,
with a comma as the field separator.
The following list displays the Token types and their data (in display order):
■ File Token
Label, version, time, filename
■ Header Token
Label, record byte count, version, event type, machine address, time (event recorded)
■ Subject Token
Label, audit session ID, UID, mode of operation, terminal type, remote IP address,
remote port
<Example> Display all audit records.
XSCF> viewaudit
file,1,2006-04-26 21:37:25.626
+00:00,20060426213725.0000000000.SCF-4-0
header,20,1,audit - start,0.0.0.0,2006-04-26 21:37:25.660 +00:00
header,43,1,authenticate,0.0.0.0,2006-04-26 22:01:28.902 +00:00
authentication,failure,,unknown user,telnet 27652 0.0.197.33
header,37,1,login - telnet,0.0.0.0,2006-04-26 22:02:26.459 +00:00
subject,1,opl,normal,telnet 50466 10.18.108.4
header,78,1,command - setprivileges,0.0.0.0,2006-04-26
22:02:43.246 +00:00
subject,1,opl,normal,telnet 50466 10.18.108.4
command,setprivileges,opl,useradm
platform access,granted
return,0
Comentarios a estos manuales