Recommended Way To Rotate Audit Log Files

Posted on 2011-10-24
Last Modified: 2013-12-27
What is the recommended approach to rotate the audit log files in /var/audit. I have one active (not terminated) audit file in this dir that just keeps getting bigger. I've read to add '/usr/sbin/audit -n' as a cron job for root in order to stop the audit process, create a new file then restart it. Then I simply move the older logs files to a secure location? Any other reccomendations? Running Solaris 10.


Question by:IT_Telephonics
    LVL 22

    Accepted Solution

    the easiest thing is to use logadm. Here is an example for audit files:
    LVL 38

    Expert Comment

    If you are using Solaris BSM, you can use "audit -n" command to rotate audit logs
    man audit
    to learn more details.

    you can also use cron to run a script to do the job.

    also have a look at the following pages:

    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Join & Write a Comment

    This tech tip describes how to install the Solaris Operating System from a tape backup that was created using the Solaris flash archive utility. I have used this procedure on the Solaris 8 and 9 OS, and it shoudl also work well on the Solaris 10 rel…
    I promised to write further about my project, and here I am.  First, I needed to setup the Primary Server.  You can read how in this article: Setup FreeBSD Server with full HDD encryption (…
    Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
    Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…

    746 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now