Analysis & Correlation of Mac Logs - SANS
Analysis & Correlation of Mac Logs - SANS
Analysis & Correlation of Mac Logs - SANS
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Audit Log Records<br />
Each record is made up <strong>of</strong> “tokens”:<br />
Header<br />
Subject<br />
Text<br />
Return<br />
Trailer<br />
!<br />
!<br />
Verify password for record type Users<br />
'root' node '/Local/Default'!<br />
!<br />
!<br />
oompa@csh.rit.edu | @iamevltwin