xref: /freebsd/contrib/openbsm/etc/audit_event (revision 595e514d0df2bac5b813d35f83e32875dbf16a83)
1#
2# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_event#43 $
3# $FreeBSD$
4#
5# The mapping between event identifiers and values is also hard-coded in
6# audit_kevents.h and audit_uevents.h, so changes must occur in both places,
7# and programs, such as the kernel, may need to be recompiled to recognize
8# those changes.  It is advisable not to change the numbering or naming of
9# kernel audit events.
10#
11# Allocation of BSM event identifier ranges:
12#
13# 0                    Reserved and invalid
14# 1     - 2047         Reserved for Solaris kernel events
15# 2048  - 5999         Reserved and unallocated
16# 6000  - 9999         Reserved for Solaris user events
17# 10000 - 32767        Reserved and unallocated
18# 32768 - 65535        Available for third party applications
19#
20# Of the third party range, OpenBSM allocates from the following ranges:
21#
22# 43000 - 44999        Reserved for OpenBSM kernel events
23# 45000 - 46999        Reserved for OpenBSM application events
24#
250:AUE_NULL:indir system call:no
261:AUE_EXIT:exit(2):pc
272:AUE_FORK:fork(2):pc
283:AUE_OPEN:open(2) - attr only:fa
294:AUE_CREAT:creat(2):fc
305:AUE_LINK:link(2):fc
316:AUE_UNLINK:unlink(2):fd
327:AUE_EXEC:exec(2):pc,ex
338:AUE_CHDIR:chdir(2):pc
349:AUE_MKNOD:mknod(2):fc
3510:AUE_CHMOD:chmod(2):fm
3611:AUE_CHOWN:chown(2):fm
3712:AUE_UMOUNT:umount(2) - old version:ad
3813:AUE_JUNK:junk:no
3914:AUE_ACCESS:access(2):fa
4015:AUE_KILL:kill(2):pc
4116:AUE_STAT:stat(2):fa
4217:AUE_LSTAT:lstat(2):fa
4318:AUE_ACCT:acct(2):ad
4419:AUE_MCTL:mctl(2):no
4520:AUE_REBOOT:reboot(2):ad
4621:AUE_SYMLINK:symlink(2):fc
4722:AUE_READLINK:readlink(2):fr
4823:AUE_EXECVE:execve(2):pc,ex
4924:AUE_CHROOT:chroot(2):pc
5025:AUE_VFORK:vfork(2):pc
5126:AUE_SETGROUPS:setgroups(2):pc
5227:AUE_SETPGRP:setpgrp(2):pc
5328:AUE_SWAPON:swapon(2):ad
5429:AUE_SETHOSTNAME:sethostname(2):ad
5530:AUE_FCNTL:fcntl(2):fm
5631:AUE_SETPRIORITY:setpriority(2):pc
5732:AUE_CONNECT:connect(2):nt
5833:AUE_ACCEPT:accept(2):nt
5934:AUE_BIND:bind(2):nt
6035:AUE_SETSOCKOPT:setsockopt(2):nt
6136:AUE_VTRACE:vtrace(2):pc
6237:AUE_SETTIMEOFDAY:settimeofday(2):ad
6338:AUE_FCHOWN:fchown(2):fm
6439:AUE_FCHMOD:fchmod(2):fm
6540:AUE_SETREUID:setreuid(2):pc
6641:AUE_SETREGID:setregid(2):pc
6742:AUE_RENAME:rename(2):fc,fd
6843:AUE_TRUNCATE:truncate(2):fw
6944:AUE_FTRUNCATE:ftruncate(2):fw
7045:AUE_FLOCK:flock(2):fm
7146:AUE_SHUTDOWN:shutdown(2):nt
7247:AUE_MKDIR:mkdir(2):fc
7348:AUE_RMDIR:rmdir(2):fd
7449:AUE_UTIMES:utimes(2):fm
7550:AUE_ADJTIME:adjtime(2):ad
7651:AUE_SETRLIMIT:setrlimit(2):pc
7752:AUE_KILLPG:killpg(2):pc
7853:AUE_NFS_SVC:nfs_svc(2):ad
7954:AUE_STATFS:statfs(2):fa
8055:AUE_FSTATFS:fstatfs(2):fa
8156:AUE_UNMOUNT:unmount(2):ad
8257:AUE_ASYNC_DAEMON:async_daemon(2):ad
8358:AUE_NFS_GETFH:nfs_getfh(2):ad
8459:AUE_SETDOMAINNAME:setdomainname(2):ad
8560:AUE_QUOTACTL:quotactl(2):ad
8661:AUE_EXPORTFS:exportfs(2):ad
8762:AUE_MOUNT:mount(2):ad
8863:AUE_SEMSYS:semsys(2):ip
8964:AUE_MSGSYS:msgsys(2):ip
9065:AUE_SHMSYS:shmsys(2):ip
9166:AUE_BSMSYS:bsmsys(2):ad
9267:AUE_RFSSYS:rfssys(2):ad
9368:AUE_FCHDIR:fchdir(2):pc
9469:AUE_FCHROOT:fchroot(2):pc
9570:AUE_VPIXSYS:vpixsys(2):no
9671:AUE_PATHCONF:pathconf(2):fa
9772:AUE_OPEN_R:open(2) - read:fr
9873:AUE_OPEN_RC:open(2) - read,creat:fc,fr,fa,fm
9974:AUE_OPEN_RT:open(2) - read,trunc:fd,fr,fa,fm
10075:AUE_OPEN_RTC:open(2) - read,creat,trunc:fc,fd,fr,fa,fm
10176:AUE_OPEN_W:open(2) - write:fw
10277:AUE_OPEN_WC:open(2) - write,creat:fc,fw,fa,fm
10378:AUE_OPEN_WT:open(2) - write,trunc:fd,fw,fa,fm
10479:AUE_OPEN_WTC:open(2) - write,creat,trunc:fc,fd,fw,fa,fm
10580:AUE_OPEN_RW:open(2) - read,write:fr,fw
10681:AUE_OPEN_RWC:open(2) - read,write,creat:fc,fw,fr,fa,fm
10782:AUE_OPEN_RWT:open(2) - read,write,trunc:fd,fr,fw,fa,fm
10883:AUE_OPEN_RWTC:open(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
10984:AUE_MSGCTL:msgctl(2) - illegal command:ip
11085:AUE_MSGCTL_RMID:msgctl(2) - IPC_RMID command:ip
11186:AUE_MSGCTL_SET:msgctl(2) - IPC_SET command:ip
11287:AUE_MSGCTL_STAT:msgctl(2) - IPC_STAT command:ip
11388:AUE_MSGGET:msgget(2):ip
11489:AUE_MSGRCV:msgrcv(2):ip
11590:AUE_MSGSND:msgsnd(2):ip
11691:AUE_SHMCTL:shmctl(2) - illegal command:ip
11792:AUE_SHMCTL_RMID:shmctl(2) - IPC_RMID command:ip
11893:AUE_SHMCTL_SET:shmctl(2) - IPC_SET command:ip
11994:AUE_SHMCTL_STAT:shmctl(2) - IPC_STAT command:ip
12095:AUE_SHMGET:shmget(2):ip
12196:AUE_SHMAT:shmat(2):ip
12297:AUE_SHMDT:shmdt(2):ip
12398:AUE_SEMCTL:semctl(2) - illegal command:ip
12499:AUE_SEMCTL_RMID:semctl(2) - IPC_RMID command:ip
125100:AUE_SEMCTL_SET:semctl(2) - IPC_SET command:ip
126101:AUE_SEMCTL_STAT:semctl(2) - IPC_STAT command:ip
127102:AUE_SEMCTL_GETNCNT:semctl(2) - GETNCNT command:ip
128103:AUE_SEMCTL_GETPID:semctl(2) - GETPID command:ip
129104:AUE_SEMCTL_GETVAL:semctl(2) - GETVAL command:ip
130105:AUE_SEMCTL_GETALL:semctl(2) - GETALL command:ip
131106:AUE_SEMCTL_GETZCNT:semctl(2) - GETZCNT command:ip
132107:AUE_SEMCTL_SETVAL:semctl(2) - SETVAL command:ip
133108:AUE_SEMCTL_SETALL:semctl(2) - SETALL command:ip
134109:AUE_SEMGET:semget(2):ip
135110:AUE_SEMOP:semop(2):ip
136111:AUE_CORE:process dumped core:fc
137112:AUE_CLOSE:close(2):cl
138113:AUE_SYSTEMBOOT:system booted:na
139114:AUE_ASYNC_DAEMON_EXIT:async_daemon(2) exited:ad
140115:AUE_NFSSVC_EXIT:nfssvc(2) exited:ad
141128:AUE_WRITEL:writel(2):no
142129:AUE_WRITEVL:writevl(2):no
143130:AUE_GETAUID:getauid(2):ad
144131:AUE_SETAUID:setauid(2):ad
145132:AUE_GETAUDIT:getaudit(2):ad
146133:AUE_SETAUDIT:setaudit(2):ad
147134:AUE_GETUSERAUDIT:getuseraudit(2):ad
148135:AUE_SETUSERAUDIT:setuseraudit(2):ad
149136:AUE_AUDITSVC:auditsvc(2):ad
150137:AUE_AUDITUSER:audituser(2):ad
151138:AUE_AUDITON:auditon(2):ad
152139:AUE_AUDITON_GTERMID:auditon(2) - GETTERMID command:ad
153140:AUE_AUDITON_STERMID:auditon(2) - SETTERMID command:ad
154141:AUE_AUDITON_GPOLICY:auditon(2) - GPOLICY command:ad
155142:AUE_AUDITON_SPOLICY:auditon(2) - SPOLICY command:ad
156143:AUE_AUDITON_GESTATE:auditon(2) - GESTATE command:ad
157144:AUE_AUDITON_SESTATE:auditon(2) - SESTATE command:ad
158145:AUE_AUDITON_GQCTRL:auditon(2) - GQCTRL command:ad
159146:AUE_AUDITON_SQCTRL:auditon(2) - SQCTRL command:ad
160147:AUE_GETKERNSTATE:getkernstate(2):ad
161148:AUE_SETKERNSTATE:setkernstate(2):ad
162149:AUE_GETPORTAUDIT:getportaudit(2):ad
163150:AUE_AUDITSTAT:auditstat(2):ad
164151:AUE_REVOKE:revoke(2):cl
165152:AUE_MAC:Solaris AUE_MAC:no
166153:AUE_ENTERPROM:enter prom:ad
167154:AUE_EXITPROM:exit prom:ad
168155:AUE_IFLOAT:Solaris AUE_IFLOAT:no
169156:AUE_PFLOAT:Solaris AUE_PFLOAT:no
170157:AUE_UPRIV:Solaris AUE_UPRIV:no
171158:AUE_IOCTL:ioctl(2):io
172173:AUE_ONESIDE:one-sided session record:nt
173174:AUE_MSGGETL:msggetl(2):ip
174175:AUE_MSGRCVL:msgrcvl(2):ip
175176:AUE_MSGSNDL:msgsndl(2):ip
176177:AUE_SEMGETL:semgetl(2):ip
177178:AUE_SHMGETL:shmgetl(2):ip
178183:AUE_SOCKET:socket(2):nt
179184:AUE_SENDTO:sendto(2):nt
180185:AUE_PIPE:pipe(2):ip
181186:AUE_SOCKETPAIR:socketpair(2):nt
182187:AUE_SEND:send(2):nt
183188:AUE_SENDMSG:sendmsg(2):nt
184189:AUE_RECV:recv(2):nt
185190:AUE_RECVMSG:recvmsg(2):nt
186191:AUE_RECVFROM:recvfrom(2):nt
187192:AUE_READ:read(2):no
188193:AUE_GETDENTS:getdents(2):no
189194:AUE_LSEEK:lseek(2):no
190195:AUE_WRITE:write(2):no
191196:AUE_WRITEV:writev(2):no
192197:AUE_NFS:nfs server:ad
193198:AUE_READV:readv(2):no
194199:AUE_OSTAT:Solaris old stat(2):fa
195200:AUE_SETUID:setuid(2):pc
196201:AUE_STIME:old stime(2):ad
197202:AUE_UTIME:old utime(2):fm
198203:AUE_NICE:old nice(2):pc
199204:AUE_OSETPGRP:Solaris old setpgrp(2):pc
200205:AUE_SETGID:setgid(2):pc
201206:AUE_READL:readl(2):no
202207:AUE_READVL:readvl(2):no
203208:AUE_FSTAT:fstat(2):fa
204209:AUE_DUP2:dup2(2):no
205210:AUE_MMAP:mmap(2):no
206211:AUE_AUDIT:audit(2):ot
207212:AUE_PRIOCNTLSYS:Solaris priocntlsys(2):pc
208213:AUE_MUNMAP:munmap(2):cl
209214:AUE_SETEGID:setegid(2):pc
210215:AUE_SETEUID:seteuid(2):pc
211216:AUE_PUTMSG:putmsg(2):nt
212217:AUE_GETMSG:getmsg(2):nt
213218:AUE_PUTPMSG:putpmsg(2):nt
214219:AUE_GETPMSG:getpmsg(2):nt
215220:AUE_AUDITSYS:audit system calls place holder:no
216221:AUE_AUDITON_GETKMASK:auditon(2) - get kernel mask:ad
217222:AUE_AUDITON_SETKMASK:auditon(2) - set kernel mask:ad
218223:AUE_AUDITON_GETCWD:auditon(2) - get cwd:ad
219224:AUE_AUDITON_GETCAR:auditon(2) - get car:ad
220225:AUE_AUDITON_GETSTAT:auditon(2) - get audit statistics:ad
221226:AUE_AUDITON_SETSTAT:auditon(2) - reset audit statistics:ad
222227:AUE_AUDITON_SETUMASK:auditon(2) - set mask per uid:ad
223228:AUE_AUDITON_SETSMASK:auditon(2) - set mask per session ID:ad
224229:AUE_AUDITON_GETCOND:auditon(2) - get audit state:ad
225230:AUE_AUDITON_SETCOND:auditon(2) - set audit state:ad
226231:AUE_AUDITON_GETCLASS:auditon(2) - get event class:ad
227232:AUE_AUDITON_SETCLASS:auditon(2) - set event class:ad
228233:AUE_UTSSYS:utssys(2) - fusers:ad
229234:AUE_STATVFS:statvfs(2):fa
230235:AUE_XSTAT:xstat(2):fa
231236:AUE_LXSTAT:lxstat(2):fa
232237:AUE_LCHOWN:lchown(2):fm
233238:AUE_MEMCNTL:memcntl(2):ot
234239:AUE_SYSINFO:sysinfo(2):ad
235240:AUE_XMKNOD:xmknod(2):fc
236241:AUE_FORK1:fork1(2):pc
237242:AUE_MODCTL:modctl(2) system call place holder:no
238243:AUE_MODLOAD:modctl(2) - load module:ad
239244:AUE_MODUNLOAD:modctl(2) - unload module:ad
240245:AUE_MODCONFIG:modctl(2) - configure module:ad
241246:AUE_MODADDMAJ:modctl(2) - bind module:ad
242247:AUE_SOCKACCEPT:getmsg-accept:nt
243248:AUE_SOCKCONNECT:putmsg-connect:nt
244249:AUE_SOCKSEND:putmsg-send:nt
245250:AUE_SOCKRECEIVE:getmsg-receive:nt
246251:AUE_ACLSET:acl(2) - SETACL comand:fm
247252:AUE_FACLSET:facl(2) - SETACL command:fm
248253:AUE_DOORFS:doorfs(2) - system call place holder:no
249254:AUE_DOORFS_DOOR_CALL:doorfs(2) - DOOR_CALL:ip
250255:AUE_DOORFS_DOOR_RETURN:doorfs(2) - DOOR_RETURN:ip
251256:AUE_DOORFS_DOOR_CREATE:doorfs(2) - DOOR_CREATE:ip
252257:AUE_DOORFS_DOOR_REVOKE:doorfs(2) - DOOR_REVOKE:ip
253258:AUE_DOORFS_DOOR_INFO:doorfs(2) - DOOR_INFO:ip
254259:AUE_DOORFS_DOOR_CRED:doorfs(2) - DOOR_CRED:ip
255260:AUE_DOORFS_DOOR_BIND:doorfs(2) - DOOR_BIND:ip
256261:AUE_DOORFS_DOOR_UNBIND:doorfs(2) - DOOR_UNBIND:ip
257262:AUE_P_ONLINE:p_online(2):ad
258263:AUE_PROCESSOR_BIND:processor_bind(2):ad
259264:AUE_INST_SYNC:inst_sync(2):ad
260265:AUE_SOCKCONFIG:configure socket:nt
261266:AUE_SETAUDIT_ADDR:setaudit_addr(2):ad
262267:AUE_GETAUDIT_ADDR:getaudit_addr(2):ad
263268:AUE_UMOUNT2:Solaris umount(2):ad
264269:AUE_FSAT:fsat(2) - place holder:no
265270:AUE_OPENAT_R:openat(2) - read:fr
266271:AUE_OPENAT_RC:openat(2) - read,creat:fc,fr,fa,fm
267272:AUE_OPENAT_RT:openat(2) - read,trunc:fd,fr,fa,fm
268273:AUE_OPENAT_RTC:openat(2) - read,creat,trunc:fc,fd,fr,fa,fm
269274:AUE_OPENAT_W:openat(2) - write:fw
270275:AUE_OPENAT_WC:openat(2) - write,creat:fc,fw,fa,fm
271276:AUE_OPENAT_WT:openat(2) - write,trunc:fd,fw,fa,fm
272277:AUE_OPENAT_WTC:openat(2) - write,creat,trunc:fc,fd,fw,fa,fm
273278:AUE_OPENAT_RW:openat(2) - read,write:fr,fw
274279:AUE_OPENAT_RWC:openat(2) - read,write,create:fc,fw,fr,fa,fm
275280:AUE_OPENAT_RWT:openat(2) - read,write,trunc:fd,fw,fr,fa,fm
276281:AUE_OPENAT_RWTC:openat(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
277282:AUE_RENAMEAT:renameat(2):fc,fd
278283:AUE_FSTATAT:fstatat(2):fa
279284:AUE_FCHOWNAT:fchownat(2):fm
280285:AUE_FUTIMESAT:futimesat(2):fm
281286:AUE_UNLINKAT:unlinkat(2):fd
282287:AUE_CLOCK_SETTIME:clock_settime(2):ad
283288:AUE_NTP_ADJTIME:ntp_adjtime(2):ad
284289:AUE_SETPPRIV:setppriv(2):pc
285290:AUE_MODDEVPLCY:modctl(2) - configure device policy:ad
286291:AUE_MODADDPRIV:modctl(2) - configure additional privilege:ad
287292:AUE_CRYPTOADM:kernel cryptographic framework:ad
288293:AUE_CONFIGKSSL:configure kernel SSL:ad
289294:AUE_BRANDSYS:brandsys(2):ot
290295:AUE_PF_POLICY_ADDRULE:Add IPsec policy rule:ad
291296:AUE_PF_POLICY_DELRULE:Delete IPsec policy rule:ad
292297:AUE_PF_POLICY_CLONE:Clone IPsec policy:ad
293298:AUE_PF_POLICY_FLIP:Flip IPsec policy:ad
294299:AUE_PF_POLICY_FLUSH:Flush IPsec policy rules:ad
295300:AUE_PF_POLICY_ALGS:Update IPsec algorithms:ad
296301:AUE_PORTFS:portfs:fa
297#
298# What follows are deprecated Darwin event numbers that may soon^H^H^H^Hnow
299# conflict with Solaris events.
300#
301301:AUE_DARWIN_GETFSSTAT:getfsstat(2):fa
302302:AUE_DARWIN_PTRACE:ptrace(2):pc
303303:AUE_DARWIN_CHFLAGS:chflags(2):fm
304304:AUE_DARWIN_FCHFLAGS:fchflags(2):fm
305305:AUE_DARWIN_PROFILE:profil(2):pc
306306:AUE_DARWIN_KTRACE:ktrace(2):pc
307307:AUE_DARWIN_SETLOGIN:setlogin(2):pc
308308:AUE_DARWIN_REBOOT:reboot(2):ad
309309:AUE_DARWIN_REVOKE:revoke(2):cl
310310:AUE_DARWIN_UMASK:umask(2):pc
311311:AUE_DARWIN_MPROTECT:mprotect(2):fm
312312:AUE_DARWIN_SETPRIORITY:setpriority(2):pc,ot
313313:AUE_DARWIN_SETTIMEOFDAY:settimeofday(2):ad
314314:AUE_DARWIN_FLOCK:flock(2):fm
315315:AUE_DARWIN_MKFIFO:mkfifo(2):fc
316316:AUE_DARWIN_POLL:poll(2):no
317317:AUE_DARWIN_SOCKETPAIR:socketpair(2):nt
318318:AUE_DARWIN_FUTIMES:futimes(2):fm
319319:AUE_DARWIN_SETSID:setsid(2):pc
320320:AUE_DARWIN_SETPRIVEXEC:setprivexec(2):pc
321321:AUE_DARWIN_NFSSVC:nfssvc(2):ad
322322:AUE_DARWIN_GETFH:getfh(2):fa
323323:AUE_DARWIN_QUOTACTL:quotactl(2):ad
324324:AUE_DARWIN_ADDPROFILE:add_profil():pc
325325:AUE_DARWIN_KDEBUGTRACE:kdebug_trace():pc
326326:AUE_DARWIN_FSTAT:fstat(2):fa
327327:AUE_DARWIN_FPATHCONF:fpathconf(2):fa
328328:AUE_DARWIN_GETDIRENTRIES:getdirentries(2):no
329329:AUE_DARWIN_TRUNCATE:truncate(2):fw
330330:AUE_DARWIN_FTRUNCATE:ftruncate(2):fw
331331:AUE_DARWIN_SYSCTL:sysctl(3):ad
332332:AUE_DARWIN_MLOCK:mlock(2):pc
333333:AUE_DARWIN_MUNLOCK:munlock(2):pc
334334:AUE_DARWIN_UNDELETE:undelete(2):fm
335335:AUE_DARWIN_GETATTRLIST:getattrlist():fa
336336:AUE_DARWIN_SETATTRLIST:setattrlist():fm
337337:AUE_DARWIN_GETDIRENTRIESATTR:getdirentriesattr():fa
338338:AUE_DARWIN_EXCHANGEDATA:exchangedata():fw
339339:AUE_DARWIN_SEARCHFS:searchfs():fa
340340:AUE_DARWIN_MINHERIT:minherit(2):pc
341341:AUE_DARWIN_SEMCONFIG:semconfig():ip
342342:AUE_DARWIN_SEMOPEN:sem_open(2):ip
343343:AUE_DARWIN_SEMCLOSE:sem_close(2):ip
344344:AUE_DARWIN_SEMUNLINK:sem_unlink(2):ip
345345:AUE_DARWIN_SHMOPEN:shm_open(2):ip
346346:AUE_DARWIN_SHMUNLINK:shm_unlink(2):ip
347347:AUE_DARWIN_LOADSHFILE:load_shared_file():fr
348348:AUE_DARWIN_RESETSHFILE:reset_shared_file():ot
349349:AUE_DARWIN_NEWSYSTEMSHREG:new_system_share_regions():ot
350350:AUE_DARWIN_PTHREADKILL:pthread_kill(2):pc
351351:AUE_DARWIN_PTHREADSIGMASK:pthread_sigmask(2):pc
352352:AUE_DARWIN_AUDITCTL:auditctl(2):ad
353353:AUE_DARWIN_RFORK:rfork(2):pc
354354:AUE_DARWIN_LCHMOD:lchmod(2):fm
355355:AUE_DARWIN_SWAPOFF:swapoff(2):ad
356356:AUE_DARWIN_INITPROCESS:init_process():pc
357357:AUE_DARWIN_MAPFD:map_fd():fa
358358:AUE_DARWIN_TASKFORPID:task_for_pid():pc
359359:AUE_DARWIN_PIDFORTASK:pid_for_task():pc
360360:AUE_DARWIN_SYSCTL_NONADMIN:sysctl() - non-admin:ot
361361:AUE_DARWIN_COPYFILE:copyfile():fr,fw
362#
363# OpenBSM-specific kernel events.
364#
36543001:AUE_GETFSSTAT:getfsstat(2):fa
36643002:AUE_PTRACE:ptrace(2):pc
36743003:AUE_CHFLAGS:chflags(2):fm
36843004:AUE_FCHFLAGS:fchflags(2):fm
36943005:AUE_PROFILE:profil(2):pc
37043006:AUE_KTRACE:ktrace(2):pc
37143007:AUE_SETLOGIN:setlogin(2):pc
37243008:AUE_OPENBSM_REVOKE:revoke(2):cl
37343009:AUE_UMASK:umask(2):pc
37443010:AUE_MPROTECT:mprotect(2):fm
37543011:AUE_MKFIFO:mkfifo(2):fc
37643012:AUE_POLL:poll(2):no
37743013:AUE_FUTIMES:futimes(2):fm
37843014:AUE_SETSID:setsid(2):pc
37943015:AUE_SETPRIVEXEC:setprivexec(2):pc
38043016:AUE_ADDPROFILE:add_profil():pc
38143017:AUE_KDEBUGTRACE:kdebug_trace():pc
38243018:AUE_OPENBSM_FSTAT:fstat(2):fa
38343019:AUE_FPATHCONF:fpathconf(2):fa
38443020:AUE_GETDIRENTRIES:getdirentries(2):no
38543021:AUE_SYSCTL:sysctl(3):ot
38643022:AUE_MLOCK:mlock(2):pc
38743023:AUE_MUNLOCK:munlock(2):pc
38843024:AUE_UNDELETE:undelete(2):fm
38943025:AUE_GETATTRLIST:getattrlist():fa
39043026:AUE_SETATTRLIST:setattrlist():fm
39143027:AUE_GETDIRENTRIESATTR:getdirentriesattr():fa
39243028:AUE_EXCHANGEDATA:exchangedata():fw
39343029:AUE_SEARCHFS:searchfs():fa
39443030:AUE_MINHERIT:minherit(2):pc
39543031:AUE_SEMCONFIG:semconfig():ip
39643032:AUE_SEMOPEN:sem_open(2):ip
39743033:AUE_SEMCLOSE:sem_close(2):ip
39843034:AUE_SEMUNLINK:sem_unlink(2):ip
39943035:AUE_SHMOPEN:shm_open(2):ip
40043036:AUE_SHMUNLINK:shm_unlink(2):ip
40143037:AUE_LOADSHFILE:load_shared_file():fr
40243038:AUE_RESETSHFILE:reset_shared_file():ot
40343039:AUE_NEWSYSTEMSHREG:new_system_share_regions():ot
40443040:AUE_PTHREADKILL:pthread_kill(2):pc
40543041:AUE_PTHREADSIGMASK:pthread_sigmask(2):pc
40643042:AUE_AUDITCTL:auditctl(2):ad
40743043:AUE_RFORK:rfork(2):pc
40843044:AUE_LCHMOD:lchmod(2):fm
40943045:AUE_SWAPOFF:swapoff(2):ad
41043046:AUE_INITPROCESS:init_process():pc
41143047:AUE_MAPFD:map_fd():fa
41243048:AUE_TASKFORPID:task_for_pid():pc
41343049:AUE_PIDFORTASK:pid_for_task():pc
41443050:AUE_SYSCTL_NONADMIN:sysctl() - non-admin:ot
41543051:AUE_COPYFILE:copyfile(2):fr,fw
41643052:AUE_LUTIMES:lutimes(2):fm
41743053:AUE_LCHFLAGS:lchflags(2):fm
41843054:AUE_SENDFILE:sendfile(2):nt
41943055:AUE_USELIB:uselib(2):fa
42043056:AUE_GETRESUID:getresuid(2):pc
42143057:AUE_SETRESUID:setresuid(2):pc
42243058:AUE_GETRESGID:getresgid(2):pc
42343059:AUE_SETRESGID:setresgid(2):pc
42443060:AUE_WAIT4:wait4(2):pc
42543061:AUE_LGETFH:lgetfh(2):fa
42643062:AUE_FHSTATFS:fhstatfs(2):fa
42743063:AUE_FHOPEN:fhopen(2):fa
42843064:AUE_FHSTAT:fhstat(2):fa
42943065:AUE_JAIL:jail(2):pc
43043066:AUE_EACCESS:eaccess(2):fa
43143067:AUE_KQUEUE:kqueue(2):no
43243068:AUE_KEVENT:kevent(2):no
43343069:AUE_FSYNC:fsync(2):fm
43443070:AUE_NMOUNT:nmount(2):ad
43543071:AUE_BDFLUSH:bdflush(2):ad
43643072:AUE_SETFSUID:setfsuid(2):ot
43743073:AUE_SETFSGID:setfsgid(2):ot
43843074:AUE_PERSONALITY:personality(2):pc
43943075:AUE_SCHED_GETSCHEDULER:getscheduler(2):ad
44043076:AUE_SCHED_SETSCHEDULER:setscheduler(2):ad
44143077:AUE_PRCTL:prctl(2):pc
44243078:AUE_GETCWD:getcwd(2):pc
44343079:AUE_CAPGET:capget(2):pc
44443080:AUE_CAPSET:capset(2):pc
44543081:AUE_PIVOT_ROOT:pivot_root(2):pc
44643082:AUE_RTPRIO::rtprio(2):pc
44743083:AUE_SCHED_GETPARAM:sched_getparam(2):ad
44843084:AUE_SCHED_SETPARAM:sched_setparam(2):ad
44943085:AUE_SCHED_GET_PRIORITY_MAX:sched_get_priority_max(2):ad
45043086:AUE_SCHED_GET_PRIORITY_MIN:sched_get_priority_min(2):ad
45143087:AUE_SCHED_RR_GET_INTERVAL:sched_rr_get_interval(2):ad
45243088:AUE_ACL_GET_FILE:acl_get_file(2):fa
45343089:AUE_ACL_SET_FILE:acl_set_file(2):fm
45443090:AUE_ACL_GET_FD:acl_get_fd(2):fa
45543091:AUE_ACL_SET_FD:acl_set_fd(2):fm
45643092:AUE_ACL_DELETE_FILE:acl_delete_file(2):fm
45743093:AUE_ACL_DELETE_FD:acl_delete_fd(2):fm
45843094:AUE_ACL_CHECK_FILE:acl_aclcheck_file(2):fa
45943095:AUE_ACL_CHECK_FD:acl_aclcheck_fd(2):fa
46043096:AUE_ACL_GET_LINK:acl_get_link(2):fa
46143097:AUE_ACL_SET_LINK:acl_set_link(2):fm
46243098:AUE_ACL_DELETE_LINK:acl_delete_link(2):fm
46343099:AUE_ACL_CHECK_LINK:acl_aclcheck_link(2):fa
46443100:AUE_SYSARCH:sysarch(2):ot
46543101:AUE_EXTATTRCTL:extattrctl(2):fm
46643102:AUE_EXTATTR_GET_FILE:extattr_get_file(2):fa
46743103:AUE_EXTATTR_SET_FILE:extattr_set_file(2):fm
46843104:AUE_EXTATTR_LIST_FILE:extattr_list_file(2):fa
46943105:AUE_EXTATTR_DELETE_FILE:extattr_delete_file(2):fm
47043106:AUE_EXTATTR_GET_FD:extattr_get_fd(2):fa
47143107:AUE_EXTATTR_SET_FD:extattr_set_fd(2):fm
47243108:AUE_EXTATTR_LIST_FD:extattr_list_fd(2):fa
47343109:AUE_EXTATTR_DELETE_FD:extattr_delete_fd(2):fm
47443110:AUE_EXTATTR_GET_LINK:extattr_get_link(2):fa
47543111:AUE_EXTATTR_SET_LINK:extattr_set_link(2):fm
47643112:AUE_EXTATTR_LIST_LINK:extattr_list_link(2):fa
47743113:AUE_EXTATTR_DELETE_LINK:extattr_delete_link(2):fm
47843114:AUE_KENV:kenv(8):ad
47943115:AUE_JAIL_ATTACH:jail_attach(2):ad
48043116:AUE_SYSCTL_WRITE:sysctl(3):ad
48143117:AUE_IOPERM:linux ioperm:ad
48243118:AUE_READDIR:readdir(3):no
48343119:AUE_IOPL:linux iopl:ad
48443120:AUE_VM86:linux vm86:pc
48543121:AUE_MAC_GET_PROC:mac_get_proc(2):pc
48643122:AUE_MAC_SET_PROC:mac_set_proc(2):pc
48743123:AUE_MAC_GET_FD:mac_get_fd(2):fa
48843124:AUE_MAC_GET_FILE:mac_get_file(2):fa
48943125:AUE_MAC_SET_FD:mac_set_fd(2):fm
49043126:AUE_MAC_SET_FILE:mac_set_file(2):fm
49143127:AUE_MAC_SYSCALL:mac_syscall(2):ad
49243128:AUE_MAC_GET_PID:mac_get_pid(2):pc
49343129:AUE_MAC_GET_LINK:mac_get_link(2):fa
49443130:AUE_MAC_SET_LINK:mac_set_link(2):fm
49543131:AUE_MAC_EXECVE:mac_execve(2):ex,pc
49643132:AUE_GETPATH_FROMFD:getpath_fromfd(2):fa
49743133:AUE_GETPATH_FROMADDR:getpath_fromaddr(2):fa
49843134:AUE_MQ_OPEN:mq_open(2):ip
49943135:AUE_MQ_SETATTR:mq_setattr(2):ip
50043136:AUE_MQ_TIMEDRECEIVE:mq_timedreceive(2):ip
50143137:AUE_MQ_TIMEDSEND:mq_timedsend(2):ip
50243138:AUE_MQ_NOTIFY:mq_notify(2):ip
50343139:AUE_MQ_UNLINK:mq_unlink(2):ip
50443140:AUE_LISTEN:listen(2):nt
50543141:AUE_MLOCKALL:mlockall(2):pc
50643142:AUE_MUNLOCKALL:munlockall(2):pc
50743143:AUE_CLOSEFROM:closefrom(2):cl
50843144:AUE_FEXECVE:fexecve(2):pc,ex
50943145:AUE_FACCESSAT:faccessat(2):fa
51043146:AUE_FCHMODAT:fchmodat(2):fm
51143147:AUE_LINKAT:linkat(2):fc
51243148:AUE_MKDIRAT:mkdirat(2):fc
51343149:AUE_MKFIFOAT:mkfifoat(2):fc
51443150:AUE_MKNODAT:mknodat(2):fc
51543151:AUE_READLINKAT:readlinkat(2):fr
51643152:AUE_SYMLINKAT:symlinkat(2):fc
51743153:AUE_MAC_GETFSSTAT:mac_getfsstat(2):fa
51843154:AUE_MAC_GET_MOUNT:mac_get_mount(2):fa
51943155:AUE_MAC_GET_LCID:mac_get_lcid(2):pc
52043156:AUE_MAC_GET_LCTX:mac_get_lctx(2):pc
52143157:AUE_MAC_SET_LCTX:mac_set_lctx(2):pc
52243158:AUE_MAC_MOUNT:mac_mount(2):ad
52343159:AUE_GETLCID:getlcid(2):pc
52443160:AUE_SETLCID:setlcid(2):pc
52543161:AUE_TASKNAMEFORPID:taskname_for_pid():pc
52643162:AUE_ACCESS_EXTENDED:access_extended(2):fa
52743163:AUE_CHMOD_EXTENDED:chmod_extended(2):fm
52843164:AUE_FCHMOD_EXTENDED:fchmod_extended(2):fm
52943165:AUE_FSTAT_EXTENDED:fstat_extended(2):fa
53043166:AUE_LSTAT_EXTENDED:lstat_extended(2):fa
53143167:AUE_MKDIR_EXTENDED:mkdir_extended(2):fc
53243168:AUE_MKFIFO_EXTENDED:mkfifo_extended(2):fc
53343169:AUE_OPEN_EXTENDED:open_extended(2) - attr only:fa
53443170:AUE_OPEN_EXTENDED_R:open_extended(2) - read:fr
53543171:AUE_OPEN_EXTENDED_RC:open_extended(2) - read,creat:fc,fr,fa,fm
53643172:AUE_OPEN_EXTENDED_RT:open_extended(2) - read,trunc:fd,fr,fa,fm
53743173:AUE_OPEN_EXTENDED_RTC:open_extended(2) - read,creat,trunc:fc,fd,fr,fa,fm
53843174:AUE_OPEN_EXTENDED_W:open_extended(2) - write:fw
53943175:AUE_OPEN_EXTENDED_WC:open_extended(2) - write,creat:fc,fw,fa,fm
54043176:AUE_OPEN_EXTENDED_WT:open_extended(2) - write,trunc:fd,fw,fa,fm
54143177:AUE_OPEN_EXTENDED_WTC:open_extended(2) - write,creat,trunc:fc,fd,fw,fa,fm
54243178:AUE_OPEN_EXTENDED_RW:open_extended(2) - read,write:fr,fw
54343179:AUE_OPEN_EXTENDED_RWC:open_extended(2) - read,write,creat:fc,fw,fr,fa,fm
54443180:AUE_OPEN_EXTENDED_RWT:open_extended(2) - read,write,trunc:fd,fr,fw,fa,fm
54543181:AUE_OPEN_EXTENDED_RWTC:open_extended(2) - read,write,creat,trunc:fc,fd,fw,fr,fa,fm
54643182:AUE_STAT_EXTENDED:stat_extended(2):fa
54743183:AUE_UMASK_EXTENDED:umask_extended(2):pc
54843184:AUE_OPENAT:openat(2) - attr only:fa
54943185:AUE_POSIX_OPENPT:posix_openpt(2):ip
55043186:AUE_CAP_NEW:cap_new(2):fm
55143187:AUE_CAP_RIGHTS_GET:cap_rights_get(2):fm
55243188:AUE_CAP_ENTER:cap_enter(2):pc
55343189:AUE_CAP_GETMODE:cap_getmode(2):pc
55443190:AUE_POSIX_SPAWN:posix_spawn(2):pc
55543191:AUE_FSGETPATH:fsgetpath(2):ot
55643192:AUE_PREAD:pread(2):no
55743193:AUE_PWRITE:pwrite(2):no
55843194:AUE_FSCTL:fsctl():fm
55943195:AUE_FFSCTL:ffsctl():fm
56043196:AUE_LPATHCONF:lpathconf(2):fa
56143197:AUE_PDFORK:pdfork(2):pc
56243198:AUE_PDKILL:pdkill(2):pc
56343199:AUE_PDGETPID:pdgetpid(2):pc
56443200:AUE_PDWAIT:pdwait(2):pc
56543201:AUE_WAIT6:wait6(2):pc
56643202:AUE_CAP_RIGHTS_LIMIT:cap_rights_limit(2):fm
56743203:AUE_CAP_IOCTLS_LIMIT:cap_ioctls_limit(2):fm
56843204:AUE_CAP_IOCTLS_GET:cap_ioctls_get(2):fm
56943205:AUE_CAP_FCNTLS_LIMIT:cap_fcntls_limit(2):fm
57043206:AUE_CAP_FCNTLS_GET:cap_fcntls_get(2):fm
57143207:AUE_BINDAT:bindat(2):nt
57243208:AUE_CONNECTAT:connectat(2):nt
57343209:AUE_CHFLAGSAT:chflagsat(2):fm
574#
575# Solaris userspace events.
576#
5776144:AUE_at_create:at-create atjob:ad
5786145:AUE_at_delete:at-delete atjob (at or atrm):ad
5796146:AUE_at_perm:at-permission:no
5806147:AUE_cron_invoke:cron-invoke:ad
5816148:AUE_crontab_create:crontab-crontab created:ad
5826149:AUE_crontab_delete:crontab-crontab deleted:ad
5836150:AUE_crontab_perm:crontab-permission:no
5846151:AUE_inetd_connect:inetd connection:na
5856152:AUE_login:login - local:lo
5866153:AUE_logout:logout - local:lo
5876154:AUE_telnet:login - telnet:lo
5886155:AUE_rlogin:login - rlogin:lo
5896156:AUE_mountd_mount:mount:na
5906157:AUE_mountd_umount:unmount:na
5916158:AUE_rshd:rsh access:lo
5926159:AUE_su:su(1):lo
5936160:AUE_halt:system halt:ad
5946161:AUE_reboot:system reboot:ad
5956162:AUE_rexecd:rexecd:lo
5966163:AUE_passwd:passwd:lo
5976164:AUE_rexd:rexd:lo
5986165:AUE_ftpd:ftp access:lo
5996166:AUE_init:init:lo
6006167:AUE_uadmin:uadmin:no
6016168:AUE_shutdown:system shutdown:ad
6026168:AUE_poweroff:system poweroff:ad
6036170:AUE_crontab_mod:crontab-modify:ad
6046171:AUE_ftpd_logout:ftp logout:lo
6056172:AUE_ssh:login - ssh:lo
6066173:AUE_role_login:role login:lo
6076180:AUE_prof_cmd: profile command:ad
6086181:AUE_filesystem_add:add filesystem:ad
6096182:AUE_filesystem_delete:delete filesystem:ad
6106183:AUE_filesystem_modify:modify filesystem:ad
6116200:AUE_allocate_succ:allocate-device success:ot
6126201:AUE_allocate_fail:allocate-device failure:ot
6136202:AUE_deallocate_succ:deallocate-device success:ot
6146203:AUE_deallocate_fail:deallocate-device failure:ot
6156204:AUE_listdevice_succ:allocate-list devices success:ot
6166205:AUE_listdevice_fail:allocate-list devices failure:ot
6176207:AUE_create_user:create user:ad
6186208:AUE_modify_user:modify user:ad
6196209:AUE_delete_user:delete user:ad
6206210:AUE_disable_user:disable user:ad
6216211:AUE_enable_user:enable users:ad
6226212:AUE_newgrp_login:newgrp login:lo
6236213:AUE_admin_authenticate:admin login:lo
6246214:AUE_kadmind_auth:authenticated kadmind request:ua
6256215:AUE_kadmind_unauth:unauthenticated kadmind req:ua
6266216:AUE_krb5kdc_as_req:kdc authentication svc request:ap
6276217:AUE_krb5kdc_tgs_req:kdc tkt-grant svc request:ap
6286218:AUE_krb5kdc_tgs_req_2ndtktmm:kdc tgs 2ndtkt mismtch:ap
6296219:AUE_krb5kdc_tgs_req_alt_tgt:kdc tgs issue alt tgt:ap
630#
631# Historic Darwin use of low event numbering space, which collided with the
632# Solaris event space.  Now obsoleted and new, higher, event numbers assigned
633# to make it easier to interpret Solaris events using the OpenBSM tools.
634#
6356171:AUE_DARWIN_audit_startup:audit startup:ad
6366172:AUE_DARWIN_audit_shutdown:audit shutdown:ad
6376300:AUE_DARWIN_sudo:sudo(1):ad
6386501:AUE_DARWIN_modify_password:modify password:ad
6396511:AUE_DARWIN_create_group:create group:ad
6406512:AUE_DARWIN_delete_group:delete group:ad
6416513:AUE_DARWIN_modify_group:modify group:ad
6426514:AUE_DARWIN_add_to_group:add to group:ad
6436515:AUE_DARWIN_remove_from_group:remove from group:ad
6446521:AUE_DARWIN_revoke_obj:revoke object priv:fm
6456600:AUE_DARWIN_lw_login:loginwindow login:lo
6466601:AUE_DARWIN_lw_logout:loginwindow logout:lo
6477000:AUE_DARWIN_auth_user:user authentication:aa
6487001:AUE_DARWIN_ssconn:SecSrvr connection setup:aa
6497002:AUE_DARWIN_ssauthorize:SecSrvr AuthEngine:aa
6507003:AUE_DARWIN_ssauthint:SecSrvr authinternal mech:aa
651#
652# Historic/third-party application allocations of event identifiers.
653#
65432800:AUE_openssh:OpenSSH login:lo
655#
656# OpenBSM-managed application event space.
657#
65845000:AUE_audit_startup:audit startup:ad
65945001:AUE_audit_shutdown:audit shutdown:ad
66045014:AUE_modify_password:modify password:ad
66145015:AUE_create_group:create group:ad
66245016:AUE_delete_group:delete group:ad
66345017:AUE_modify_group:modify group:ad
66445018:AUE_add_to_group:add to group:ad
66545019:AUE_remove_from_group:remove from group:ad
66645020:AUE_revoke_obj:revoke object priv:fm
66745021:AUE_lw_login:loginwindow login:lo
66845022:AUE_lw_logout:loginwindow logout:lo
66945023:AUE_auth_user:user authentication:aa
67045024:AUE_ssconn:SecSrvr connection setup:aa
67145025:AUE_ssauthorize:SecSrvr AuthEngine:aa
67245026:AUE_ssauthint:SecSrvr authinternal mech:aa
67345027:AUE_calife:Calife:ad
67445028:AUE_sudo:sudo(1):aa
67545029:AUE_audit_recovery:audit crash recovery:ad
67645030:AUE_ssauthmech:SecSrvr AuthMechanism:aa
677