xref: /freebsd/contrib/openbsm/bin/audit/audit.8 (revision ca0716f5714781ac39461f60647d795321921363)
1.\" Copyright (c) 2004 Apple Computer, Inc.
2.\" All rights reserved.
3.\"
4.\" @APPLE_BSD_LICENSE_HEADER_START@
5.\"
6.\" Redistribution and use in source and binary forms, with or without
7.\" modification, are permitted provided that the following conditions
8.\" are met:
9.\"
10.\" 1.  Redistributions of source code must retain the above copyright
11.\"     notice, this list of conditions and the following disclaimer.
12.\" 2.  Redistributions in binary form must reproduce the above copyright
13.\"     notice, this list of conditions and the following disclaimer in the
14.\"     documentation and/or other materials provided with the distribution.
15.\" 3.  Neither the name of Apple Computer, Inc. ("Apple") nor the names of
16.\"     its contributors may be used to endorse or promote products derived
17.\"     from this software without specific prior written permission.
18.\"
19.\" THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
20.\" EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
21.\" WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
22.\" DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
23.\" DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
24.\" (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
25.\" LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
26.\" ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
28.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
29.\"
30.\" @APPLE_BSD_LICENSE_HEADER_END@
31.\"
32.\" $P4: //depot/projects/trustedbsd/openbsm/bin/audit/audit.8#2 $
33.\"
34.Dd Jan 24, 2004
35.Dt AUDIT 8
36.Os
37.Sh NAME
38.Nm audit
39.Nd audit management utility
40.Sh SYNOPSIS
41.Nm audit
42.Op Fl nst
43.Op Ar file
44.Sh DESCRIPTION
45The
46.Nm
47utility controls the state of auditing system. The optional
48.Ar file
49operand specifies the location of the audit control input file (default
50/etc/security/audit_control).
51.Pp
52The options are as follows:
53.Bl -tag -width Ds
54.It Fl n
55Forces the audit system to close the existing audit log file and rotate to
56a new log file in a location specified in the audit control file.
57.It Fl s
58Specifies that the audit system should [re]synchronize its
59configuration from the audit control file.  A new log file will be
60created.
61.It Fl t
62Specifies that the audit system should terminate.  Log files are closed
63and renamed to indicate the time of the shutdown.
64.El
65.Sh NOTES
66The auditd(8) daemon must already be running.
67.Sh FILES
68.Bl -tag -width "/etc/security/audit_control" -compact
69.It Pa /etc/security/audit_control
70Default audit policy file used to configure the auditing system.
71.El
72.Sh SEE ALSO
73.Xr auditd 8
74.Xr audit_control 5
75.Sh AUTHORS
76This software was created by McAfee Research, the security research division
77of McAfee, Inc., under contract to Apple Computer Inc.
78Additional authors include Wayne Salamon, Robert Watson, and SPARTA Inc.
79.Pp
80The Basic Security Module (BSM) interface to audit records and audit event
81stream format were defined by Sun Microsystems.
82.Sh HISTORY
83The OpenBSM implementation was created by McAfee Research, the security
84division of McAfee Inc., under contract to Apple Computer Inc. in 2004.
85It was subsequently adopted by the TrustedBSD Project as the foundation for
86the OpenBSM distribution.
87