18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

18-18 Monitoring, Auditing, and Reporting<br />

Example 4: Excluding information in a filter<br />

You can explicitly exclude certain types <strong>of</strong> audit information by<br />

placing the word “not” in front <strong>of</strong> a field. For example, the custom<br />

filter shown below will display all audit records EXCEPT network<br />

traffic records originating for the source IP address 172.17.9.28:<br />

not type AUDIT_T_NETTRAFFIC and src_ip 172.17.9.28<br />

where:<br />

Table 18-2. Custom audit filter fields<br />

Field Description<br />

not type AUDIT_T_NETTRAFFIC—This field will exclude any network<br />

traffic-based audit events.<br />

src_ip 172.17.9.28—This field will filter for all non-network traffic<br />

audit records generated from the source address 172.17.9.28.<br />

facility Specify an event facility code (such as AUDIT_F_LOGIN, AUDIT_F_PROXY, etc.). For a complete list <strong>of</strong><br />

the available facility codes, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the srole command and then enter<br />

the following command: acat -c | more<br />

type Specify an event type code (for example, type AUDIT_T_NETTRAFFIC). For a complete list <strong>of</strong> the<br />

available type codes, at a <strong>Sidewinder</strong> <strong>G2</strong> prompt, enter the srole command and then enter the<br />

following command: acat -c | more<br />

pid Specify the process ID <strong>of</strong> the auditing process.<br />

pgid Specify the process group ID <strong>of</strong> the auditing process.<br />

ruser Specify the real user ID <strong>of</strong> the auditing process.<br />

euser Specify the effective user ID <strong>of</strong> the auditing process.<br />

username Specify a user name.<br />

src_ip Specify the source IP address using the dotted decimal IP version 4 notation, with optional mask bits<br />

separated by a slash (/).<br />

dst_ip Specify the destination IP address using the dotted decimal IP version 4 notation, with optional mask<br />

bits separated by a slash (/).<br />

src_port Specify the TCP or UDP source port.<br />

dst_port Specify the TCP or UDP destination port.<br />

More . . .

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!