setaudit —
specify audit configurations on a
process
setaudit |
[-46U] [-a
auid] [-m
mask] [-s
source] [-p
port] command ... |
setaudit is a tool to specify audit
configurations on a process.
The following options are available:
-4
- Use IPv4.
-6
- Use IPv6.
-U
- Update audit session state rather than overwriting it. By default,
setaudit will overwrite the entire audit session
state using the specified parameters. If -U is
specified, only the parameters given on the command line will be updated,
leaving the rest unchanged.
-a
auid
- Audit user ID or user name.
-m
mask
- String representation of an audit mask.
-s
source
- IPv4 or IPv6 address of a Terminal ID.
-p
port
- Port of a Terminal ID.
Enable all exe related audit events performed by
command and its child processes:
# setaudit -m ex command