18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

18<br />

Overview <strong>of</strong> the audit process<br />

Figure 18-1. The audit<br />

flow<br />

18-2 Monitoring, Auditing, and Reporting<br />

Monitoring<br />

Using the Admin Console,<br />

you can monitor <strong>Sidewinder</strong><br />

<strong>G2</strong> activity and status in<br />

real-time.<br />

Auditing<br />

auditd reads /dev/audit<br />

and places the<br />

information into<br />

audit.raw.<br />

This is the recorded<br />

audit stream. This is now<br />

"history" and contains<br />

everything that might<br />

be worth viewing.<br />

Reporting<br />

programs kernel<br />

live audit stream<br />

aka /dev/audit.....<br />

auditd<br />

/var/log/audit.raw<br />

auditdbd<br />

auditdb<br />

auditbotd<br />

auditbotd has a threshold<br />

and can trigger an event<br />

response (see Chapter 17).<br />

Using the Admin Console,<br />

you can filter and view<br />

audit information.<br />

This is an SQL database <strong>of</strong><br />

information maintained by<br />

auditdbd. It contains all<br />

relevant audit information.<br />

Using the Admin Console,<br />

you can generate detailed,<br />

easy-to-read reports.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!