We would like to enable auditing for a specific set of files on a
Digital Unix 4.0, Patch Kit 5 system.
We can successfully turn on auditing, and audit the "object access"
class of events, and get overwhelmed by data.
If, instead, we set the auditmask style to "object selection", and then
enable particular objects, we get nothing.
The auditmask command confirms that object selection is on,
and the auditmask -q "object" command confirms that object
selection is on for the object. But test object accesses
produce no audit data whatsoever, even after an "audit -d"
to make sure the audit daemon's buffer is flushed.
What am I missing?
- Saul
Received on Fri Mar 06 1998 - 19:54:18 NZDT