18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

18-6 Monitoring, Auditing, and Reporting<br />

The auditbot daemon tracks these events and uses information in<br />

its configuration file to determine when the data might be indicating<br />

a problem, such as an attempted break-in. For more information<br />

on configuring auditbots (alarms) and event responses, refer<br />

to Chapter 17.<br />

auditdbd—This is the daemon that maintains the audit database.<br />

auditdbd monitors the audit stream and sends reporting<br />

information to be stored in the MySQL database called auditdb.<br />

The auditdbd server is disabled by default.<br />

Note: Reporting services are not available until the auditdbd server is enabled. For<br />

information on enabling the auditdbd server, see “Enabling and disabling servers” on<br />

page 3-30.<br />

To view a list <strong>of</strong> audit databases, enter the following command:<br />

cf audit listdb<br />

A list <strong>of</strong> audit databases appears. The database named auditdb_1<br />

generally contains the previous days’s information. The database<br />

named auditdb_2 is generally from two days ago, and so on.<br />

Understanding audit file names<br />

The /var/log/audit.raw files contains all audit information and<br />

network probe audits contained on the <strong>Sidewinder</strong> <strong>G2</strong> in a binary<br />

format. When the file is rolled, a timestamp is appended to the file<br />

name. The easiest method for viewing the contents <strong>of</strong> the audit.raw<br />

files is to use the Admin Console’s Audit Viewing window. Refer to<br />

“Viewing audit information” on page 18-7.<br />

Tip: If you prefer to view the file contents via command line, refer to the showaudit<br />

and acat man pages.<br />

Audit files use one <strong>of</strong> two file suffixes:<br />

*.gz—This suffix is for files in compressed format. These files may<br />

be decompressed using acat or showaudit. You also have the<br />

option <strong>of</strong> using the gunzip program. (For information on using<br />

acat or showaudit, refer to the appropriate man pages.)<br />

*.raw—This suffix is for files in raw audit format. These are binary<br />

formatted files that can be viewed in ASCII format using the Admin<br />

Console (or if you prefer using the command line, via the<br />

showaudit or acat programs).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!