audit_tool Q

From: dompie (kdom@mail.mobistar.be)
Date: 04/11/03


From: kdom@mail.mobistar.be (dompie)
Date: 11 Apr 2003 05:47:37 -0700

Hi,

I have the following entry in the audit_log:
"
audit_id: 0 ruid/euid: 0/0
pid: 10076 ppid: 9956 cttydev: (6,1)
event: open
char param: /unicenter/em/scripts/unifstat.awk
flags: 0 : read
parent ino: 1198
inode id: 1224 inode dev: (2659,253641) [regular file]
object mode: 0555
result: 3 (0x3)
cpu, seq#: 0x0, 34774
ip address: 175.175.16.152 (lebrun)
timestamp: Fri Apr 11 14:00:05.71 2003 CEST
"

I there a way that I can know on what TTY this command has been
launched?
This way I can use the 'w' cmd with 'ps' to get person that logged on
'root' and typed that command.
(what's does the cttydev field mean?)

Any help much appreciated!

Kd



Relevant Pages

  • Re: Posix sucks, Linux sucks, I want my compatibility back
    ... scripts by redefining the flags for the 'tail' command. ... That is only if FC5 is mandatory for the user, ...
    (comp.unix.shell)
  • Re: Mex error in 64-bit 2008a Mac OS X beta
    ... before the command to escape out to the shell and run it, ... The output of mex -v -g is given below. ... -> CXX flags: ... -> Link flags: ...
    (comp.soft-sys.matlab)
  • Re: Command-line parameter parsing
    ... As it chances I am doing a command line processor so the issue is live ... Long flags are prefixed with a --. ... Flags may have an additional single string attached to them in the form ... In the popt style as ...
    (comp.programming)
  • Re: Posix sucks, Linux sucks, I want my compatibility back
    ... scripts by redefining the flags for the 'tail' command. ... Can anyone suggest a good way to obtain the same behavior with another built in command? ... I do my own sysadmin at home on this linux box though and I don't use GUI's for any sysadmin, I prefer konsole and vi. ...
    (comp.unix.shell)
  • Re: Posix sucks, Linux sucks, I want my compatibility back
    ... scripts by redefining the flags for the 'tail' command. ... Can anyone suggest a good way to obtain the same behavior with another built in command? ... I do my own sysadmin at home on this linux box though and I don't use GUI's for any sysadmin, I prefer konsole and vi. ...
    (comp.unix.shell)