![]() |
![]()
| ![]() |
![]()
NAME
SYNOPSIS
DESCRIPTIONBSMtrace is a utility that processes audit trails, or real-time audit feeds provided by audit pipes. It loads a set of finite state machines or sequences from the supplied configuration file and watches the audit streams for instances of these sequences. For more information, the example bsmtrace.conf file should be reviewed. It operates by reading a configuration file that lists sequences which should result in actions. The default configuration file is /etc/bsmtrace.conf. BSM records are taken from /dev/auditpipe and run through a finite state machine which attempts to match a stream of records to defined sequences. OPTIONSDIAGNOSTICSThe FILES
SEE ALSOAUTHORSAaron L. Meihm
⟨alm@freebsd.org⟩
|