Skip to main content
Skip table of contents

Catch All : Solaris 10 Audit

Classification

Rule Name

Rule Type

Classification

Common Event

Catch All : Solaris 10 AuditBase RuleOther Audit SuccessGeneral Audit
Solaris nfssvc(2) exited okSub RuleStartup and ShutdownProcess/Service Stopped
Solaris sendto(2) okSub RuleInformationFilestream Information
Solaris sendmsg(2) okSub RuleInformationFilestream Information
Solaris send(2) okSub RuleInformationFilestream Information
Solaris putpmsg(2) okSub RuleInformationFilestream Information
Solaris putmsg-send okSub RuleInformationFilestream Information
Solaris putmsg-connect okSub RuleInformationFilestream Information
Solaris putmsg(2) okSub RuleInformationFilestream Information
Solaris unmount(2) failedSub RuleAccess FailureClose Object Failure
Solaris unmount failedSub RuleAccess FailureClose Object Failure
Solaris unlinkat(2) failedSub RuleAccess FailureClose Object Failure
Solaris unlink(2) failedSub RuleAccess FailureClose Object Failure
Solaris umount2(2) failedSub RuleAccess FailureClose Object Failure
Solaris close(2) failedSub RuleAccess FailureClose Object Failure
Solaris xstat(2) failedSub RuleAccess FailureAccess Object Failure
Solaris sysinfo(2) failedSub RuleAccess FailureAccess Object Failure
Solaris semgetl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris semget(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readvl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readv(2) failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get audit statistics failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get audit state failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get audit policy flags failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - GESTATE command failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - GETTERMID command failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get queue cntrl param failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get kernel mask failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get event class failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get curr working dir failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - get curr active root failedSub RuleAccess FailureAccess Object Failure
Solaris doorfs(2) - DOOR_UNBIND failedSub RuleAccess FailureAccess Object Failure
Solaris doorfs(2) - DOOR_BIND failedSub RuleAccess FailureAccess Object Failure
Solaris chroot(2) failedSub RuleAccess FailureAccess Object Failure
Solaris chdir(2) failedSub RuleAccess FailureAccess Object Failure
Solaris auditstat(2) failedSub RuleAccess FailureAccess Object Failure
Solaris auditon(2) - reset audit statistics failedSub RuleAccess FailureAccess Object Failure
Solaris ioctl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getuseraudit(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getportaudit(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getkernstate(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getdents(2) failedSub RuleAccess FailureAccess Object Failure
Solaris fchroot(2) failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read failedSub RuleAccess FailureAccess Object Failure
Solaris nfs_getfh(2) failedSub RuleAccess FailureAccess Object Failure
Solaris msgctl(2) - IPC_STAT command failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris semgetl(2) okSub RuleAccess SuccessObject Read
Solaris semget(2) okSub RuleAccess SuccessObject Read
Solaris semctl(2) - IPC_STAT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETZCNT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETVAL command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETPID command okSub RuleAccess SuccessObject Read
Solaris getportaudit(2) okSub RuleAccess SuccessObject Read
Solaris getkernstate(2) okSub RuleAccess SuccessObject Read
Solaris getdents(2) okSub RuleAccess SuccessObject Read
Solaris xstat(2) okSub RuleAccess SuccessObject Read
Solaris sysinfo(2) okSub RuleAccess SuccessObject Read
Solaris open(2) - read,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - read okSub RuleAccess SuccessObject Read
Solaris nfs_getfh(2) okSub RuleAccess SuccessObject Read
Solaris msgctl(2) - IPC_STAT command okSub RuleAccess SuccessObject Read
Solaris ioctl(2) okSub RuleAccess SuccessObject Read
Solaris getuseraudit(2) okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write okSub RuleAccess SuccessObject Read
Solaris open(2) - read,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - read okSub RuleAccess SuccessObject Read
Solaris open(2) - write,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - write,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - write okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,creat,trunc okSub RuleAccess SuccessObject Read
Solaris read(2) okSub RuleAccess SuccessObject Read
Solaris p_online(2) okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - write okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETNCNT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETALL command okSub RuleAccess SuccessObject Read
Solaris readvl(2) okSub RuleAccess SuccessObject Read
Solaris readv(2) okSub RuleAccess SuccessObject Read
Solaris readlink(2) okSub RuleAccess SuccessObject Read
Solaris readl(2) okSub RuleAccess SuccessObject Read
Solaris kdc tkt-grant svc request okSub RuleAuthentication SuccessAuthentication Activity
Solaris kdc tgs issue alt tgt okSub RuleAuthentication SuccessAuthentication Activity
Solaris kdc authentication svc request okSub RuleAuthentication SuccessAuthentication Activity
Solaris unauthenticated kadmind req okSub RuleAuthentication SuccessAuthentication Activity
Solaris su okSub RuleAuthentication SuccessAuthentication Activity
Solaris ftp access okSub RuleAuthentication SuccessAuthentication Activity
Solaris authenticated kadmind request okSub RuleAuthentication SuccessAuthentication Activity
Solaris open(2) - read,write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write failedSub RuleAccess FailureAccess Object Failure
Solaris readlink(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris read(2) failedSub RuleAccess FailureAccess Object Failure
Solaris p_online(2) failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris renameat(2) failedSub RuleAccess FailureRename Object Failure
Solaris rename(2) failedSub RuleAccess FailureRename Object Failure
Solaris accept(2) failedSub RuleAccess FailureInitialize Object Failure
Solaris setgroups(2) okSub RuleAccount ModifiedGroup Attribute Modified
Solaris setegid(2) okSub RuleAccount ModifiedGroup Attribute Modified
Solaris setgid(2) okSub RuleAccount ModifiedGroup Attribute Modified
Solaris setregid(2) okSub RuleAccount ModifiedGroup Attribute Modified
Solaris setkernstate(2) okSub RuleConfigurationConfiguration Modified : System
Solaris sethostname(2) okSub RuleConfigurationConfiguration Modified : System
Solaris setdomainname(2) okSub RuleConfigurationConfiguration Modified : System
Solaris semctl(2) - SETVAL command okSub RuleConfigurationConfiguration Modified : System
Solaris semctl(2) - SETALL command okSub RuleConfigurationConfiguration Modified : System
Solaris adjtime(2) okSub RuleConfigurationConfiguration Modified : System
Solaris add serial port okSub RuleConfigurationConfiguration Modified : System
Solaris add scheduled job okSub RuleConfigurationConfiguration Modified : System
Solaris add printer okSub RuleConfigurationConfiguration Modified : System
Solaris add filesystem okSub RuleConfigurationConfiguration Modified : System
Solaris configure socket okSub RuleConfigurationConfiguration Modified : System
Solaris configure kernel SSL okSub RuleConfigurationConfiguration Modified : System
Solaris bind(2) okSub RuleConfigurationConfiguration Modified : System
Solaris at-create atjob okSub RuleConfigurationConfiguration Modified : System
Solaris async_daemon(2) exited okSub RuleConfigurationConfiguration Modified : System
Solaris async_daemon(2) okSub RuleConfigurationConfiguration Modified : System
Solaris setrlimit(2) okSub RuleConfigurationConfiguration Modified : System
Solaris setpriority(2) okSub RuleConfigurationConfiguration Modified : System
Solaris flock(2) okSub RuleConfigurationConfiguration Modified : System
Solaris crontab-modify okSub RuleConfigurationConfiguration Modified : System
Solaris crontab-crontab created okSub RuleConfigurationConfiguration Modified : System
Solaris connect(2) okSub RuleConfigurationConfiguration Modified : System
Solaris init(1m) okSub RuleConfigurationConfiguration Modified : System
Solaris utimes(2) okSub RuleConfigurationConfiguration Modified : System
Solaris rsh access failedSub RuleAuthentication FailureUser Logon Failure
Solaris newgrp login failedSub RuleAuthentication FailureUser Logon Failure
Solaris login - zlogin failedSub RuleAuthentication FailureUser Logon Failure
Solaris login - telnet failedSub RuleAuthentication FailureUser Logon Failure
Solaris login - ssh failedSub RuleAuthentication FailureUser Logon Failure
Solaris login - rlogin failedSub RuleAuthentication FailureUser Logon Failure
Solaris login - local failedSub RuleAuthentication FailureUser Logon Failure
Solaris ftp access failedSub RuleAuthentication FailureUser Logon Failure
Solaris admin login failedSub RuleAuthentication FailureUser Logon Failure
Solaris writevl(2) failedSub RuleAccess FailureModify Object Failure
Solaris writev(2) failedSub RuleAccess FailureModify Object Failure
Solaris writel(2) failedSub RuleAccess FailureModify Object Failure
Solaris write(2) failedSub RuleAccess FailureModify Object Failure
Solaris utimes(2) failedSub RuleAccess FailureModify Object Failure
Solaris setuseraudit(2) failedSub RuleAccess FailureModify Object Failure
Solaris add printer failedSub RuleAccess FailureModify Object Failure
Solaris add network attributes failedSub RuleAccess FailureModify Object Failure
Solaris add filesystem failedSub RuleAccess FailureModify Object Failure
Solaris acl(2) - SETACL command failedSub RuleAccess FailureModify Object Failure
Solaris acct(2) failedSub RuleAccess FailureModify Object Failure
Solaris chmod(2) failedSub RuleAccess FailureModify Object Failure
Solaris audit(2) failedSub RuleAccess FailureModify Object Failure
Solaris at-permission failedSub RuleAccess FailureModify Object Failure
Solaris add user/user attributes failedSub RuleAccess FailureModify Object Failure
Solaris add serial port failedSub RuleAccess FailureModify Object Failure
Solaris add scheduled job failedSub RuleAccess FailureModify Object Failure
Solaris enable user failedSub RuleAccess FailureModify Object Failure
Solaris disable user failedSub RuleAccess FailureModify Object Failure
Solaris delete user/user attributes failedSub RuleAccess FailureModify Object Failure
Solaris crontab-persmisson failedSub RuleAccess FailureModify Object Failure
Solaris crontab-modify failedSub RuleAccess FailureModify Object Failure
Solaris chown(2) failedSub RuleAccess FailureModify Object Failure
Solaris modctl(2) - configure addtl priv failedSub RuleAccess FailureModify Object Failure
Solaris lchown(2) failedSub RuleAccess FailureModify Object Failure
Solaris futimesat(2) failedSub RuleAccess FailureModify Object Failure
Solaris fchownat(2) failedSub RuleAccess FailureModify Object Failure
Solaris fchown(2) failedSub RuleAccess FailureModify Object Failure
Solaris fchmod(2) failedSub RuleAccess FailureModify Object Failure
Solaris modify serial port failedSub RuleAccess FailureModify Object Failure
Solaris modify scheduled job failedSub RuleAccess FailureModify Object Failure
Solaris modify printer failedSub RuleAccess FailureModify Object Failure
Solaris modify network attributes failedSub RuleAccess FailureModify Object Failure
Solaris modify filesystem failedSub RuleAccess FailureModify Object Failure
Solaris modctl(2) - configure device policy failedSub RuleAccess FailureModify Object Failure
Solaris utime(2) failedSub RuleAccess FailureModify Object Failure
Solaris setuid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setpgrp(2) failedSub RuleAccess FailureModify Object Failure
Solaris setgid(2) failedSub RuleAccess FailureModify Object Failure
Solaris modify user/user attributes failedSub RuleAccess FailureModify Object Failure
Solaris modify user failedSub RuleAccess FailureModify Object Failure
Solaris setauid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setaudit_addr(2) failedSub RuleAccess FailureModify Object Failure
Solaris screenlock - unlock okSub RuleAuthentication SuccessUser Logon
Solaris rsh access okSub RuleAuthentication SuccessUser Logon
Solaris role login okSub RuleAuthentication SuccessUser Logon
Solaris newgrp login okSub RuleAuthentication SuccessUser Logon
Solaris login - zlogin okSub RuleAuthentication SuccessUser Logon
Solaris login - telnet okSub RuleAuthentication SuccessUser Logon
Solaris login - ssh okSub RuleAuthentication SuccessUser Logon
Solaris login - rlogin okSub RuleAuthentication SuccessUser Logon
Solaris login - local okSub RuleAuthentication SuccessUser Logon
Solaris admin login okSub RuleAuthentication SuccessUser Logon
Solaris semctl(2) - IPC_RMID command okSub RuleAccess SuccessObject Deleted/Removed
Solaris rmdir(2) okSub RuleAccess SuccessObject Deleted/Removed
Solaris msgctl(2) - IPC_RMID command okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete serial port okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete printer okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete network attributes okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete filesystem okSub RuleAccess SuccessObject Deleted/Removed
Solaris ftruncate(2) okSub RuleAccess SuccessObject Initialized
Solaris truncate(2) okSub RuleAccess SuccessObject Initialized
Solaris rmdir(2) failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete user failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete serial port failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete scheduled job failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete printer failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete network attributes failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete filesystem failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris crontab-crontab deleted failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris at-delete atjob (at or atrm) failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris xmknod(2) failedSub RuleAccess FailureCreate Object Failure
Solaris socket(2) failedSub RuleAccess FailureCreate Object Failure
Solaris pipe(2) failedSub RuleAccess FailureCreate Object Failure
Solaris mknod(2) failedSub RuleAccess FailureCreate Object Failure
Solaris mkdir(2) failedSub RuleAccess FailureCreate Object Failure
Solaris crontab-crontab created failedSub RuleAccess FailureCreate Object Failure
Solaris create user failedSub RuleAccess FailureCreate Object Failure
Solaris creat(2) failedSub RuleAccess FailureCreate Object Failure
Solaris at-create atjob failedSub RuleAccess FailureCreate Object Failure
Solaris crontab-persmisson okSub RuleAccess GrantedPrivilege Granted
Solaris fchownat(2) okSub RulePolicyPolicy Modified : Object
Solaris fchown(2) okSub RulePolicyPolicy Modified : Object
Solaris fchmod(2) okSub RulePolicyPolicy Modified : Object
Solaris settimeofday(2) failedSub RuleWarningFailed System Time Change
Solaris stime(2) failedSub RuleWarningFailed System Time Change
Solaris async_daemon(2) exited failedSub RuleErrorFailed Local NFS Asynch I/O Server
Solaris async_daemon(2) failedSub RuleErrorFailed Local NFS Asynch I/O Server
Solaris clock_settime(3RT) failedSub RuleWarningFailed High Resolution Clock Operation
Solaris configure socket failedSub RuleWarningFailed Socket Configuration
Solaris deallocate-device failure failedSub RuleErrorFailed Device De-Allocation
Solaris dup2(2) failedSub RuleErrorFailed File Descriptor Duplication
Solaris truncate(2) failedSub RuleWarningFailed To Set File Length
Solaris ftruncate(2) failedSub RuleWarningFailed To Set File Length
Solaris getpmsg(2) failedSub RuleErrorFailed To Accept Message
Solaris getmsg-receive failedSub RuleErrorFailed To Accept Message
Solaris swapon(2) okSub RuleConfigurationConfiguration Modified : System
Solaris socketpair(2) okSub RuleConfigurationConfiguration Modified : System
Solaris settimeofday(2) okSub RuleConfigurationConfiguration Modified : System
Solaris setsockopt(2) okSub RuleConfigurationConfiguration Modified : System
Solaris modify serial port okSub RuleConfigurationConfiguration Modified : System
Solaris modify scheduled job okSub RuleConfigurationConfiguration Modified : System
Solaris modify printer okSub RuleConfigurationConfiguration Modified : System
Solaris modify network attributes okSub RuleConfigurationConfiguration Modified : System
Solaris mmap(2) okSub RuleConfigurationConfiguration Modified : System
Solaris link(2) okSub RuleConfigurationConfiguration Modified : System
Solaris quotactl(2) okSub RuleConfigurationConfiguration Modified : System
Solaris pipe(2) okSub RuleConfigurationConfiguration Modified : System
Solaris stime(2) okSub RuleConfigurationConfiguration Modified : System
Solaris setpgrp(2) okSub RuleConfigurationConfiguration Modified : System
Solaris nice(2) okSub RuleConfigurationConfiguration Modified : System
Solaris ntp_adjtime(2) okSub RuleConfigurationConfiguration Modified : System
Solaris add network attributes okSub RuleConfigurationConfiguration Loaded : System
Solaris enable user okSub RuleAccess GrantedAccount Enabled
Solaris disable user okSub RuleAccess RevokedAccount Disabled
Solaris semctl(2) - illegal command okSub RuleSuspiciousSuspicious Activity
Solaris msgctl(2) - illegal command okSub RuleInformationFile System Mounted
Solaris mount(2) okSub RuleInformationFile System Mounted
Solaris mount okSub RuleInformationFile System Mounted
Solaris reboot(2) okSub RuleStartup and ShutdownSystem Restarted
Solaris reboot(1m) okSub RuleStartup and ShutdownSystem Restarted
Solaris access(2) failedSub RuleErrorFailed File Access Check
Solaris auditon(2) - set queue cntrl param failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set mask per sess ID failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set mask per audit uid failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set kernel mask failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set event class failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set audit state failedSub RuleErrorFailed Auditing Set
Solaris auditon(2) - set audit policy flags failedSub RuleErrorFailed Auditing Set
Solaris connect(2) failedSub RuleErrorFailed Socket Connection
Solaris flock(2) failedSub RuleOther Audit FailureFailed Advisory Lock Apply/Remove
Solaris indir system call failedSub RuleErrorFailed System Call
Solaris killpg(2) failedSub RuleWarningFailed Process Signal Send
Solaris kill(2) failedSub RuleWarningFailed Process Signal Send
Solaris modctl(2) - load module failedSub RuleErrorFailed To Load Module
Solaris modctl(2) - no longer generated failedSub RuleErrorFailed Module Execution
Solaris nfs_svc(2) failedSub RuleErrorFailed NFS Service Startup
Solaris nfs server failedSub RuleErrorFailed NFS Service Startup
Solaris nfssvc(2) exited failedSub RuleErrorFailed NFS Service Stop
Solaris ntp_adjtime(2) failedSub RuleWarningFailed Local Clock Properties Change
Solaris screenlock - lock failedSub RuleWarningFailed Screen Lock
Solaris shmdt(2) failedSub RuleErrorFailed Shared Memory Operation
Solaris shmat(2) failedSub RuleErrorFailed Shared Memory Operation
Solaris lchown(2) okSub RuleAccess GrantedOwnership Granted
Solaris chown(2) okSub RuleAccess GrantedOwnership Granted
Solaris modify filesystem okSub RuleAccess SuccessObject Modified
Solaris futimesat(2) okSub RuleAccess SuccessObject Modified
Solaris getaudit(2) okSub RuleOther Audit SuccessProcess Auditing Address Received
Solaris modctl(2) - unload module okSub RuleOther AuditModule Unloaded
Solaris setaudit(2) failedSub RuleAccess FailureModify Object Failure
Solaris semctl(2) - SETVAL command failedSub RuleAccess FailureModify Object Failure
Solaris semctl(2) - SETALL command failedSub RuleAccess FailureModify Object Failure
Solaris profile command failedSub RuleAccess FailureModify Object Failure
Solaris setkernstate(2) failedSub RuleAccess FailureModify Object Failure
Solaris sethostname(2) failedSub RuleAccess FailureModify Object Failure
Solaris setgroups(2) failedSub RuleAccess FailureModify Object Failure
Solaris seteuid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setegid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setdomainname(2) failedSub RuleAccess FailureModify Object Failure
Solaris setsockopt(2) failedSub RuleAccess FailureModify Object Failure
Solaris setrlimit(2) failedSub RuleAccess FailureModify Object Failure
Solaris setreuid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setregid(2) failedSub RuleAccess FailureModify Object Failure
Solaris setpriority(2) failedSub RuleAccess FailureModify Object Failure
Solaris setppriv(2) failedSub RuleAccess FailureModify Object Failure
Solaris zoneadmd failedSub RuleAccess FailureCommand Execution Failure
Solaris uadmin(1m) failedSub RuleAccess FailureCommand Execution Failure
Solaris shmctl(2) - IPC_STAT command failedSub RuleAccess FailureCommand Execution Failure
Solaris shmctl(2) - IPC_SET command failedSub RuleAccess FailureCommand Execution Failure
Solaris shmctl(2) - IPC_RMID command failedSub RuleAccess FailureCommand Execution Failure
Solaris shmctl(2) - illegal command failedSub RuleAccess FailureCommand Execution Failure
Solaris cron-invoke failedSub RuleAccess FailureCommand Execution Failure
Solaris auditon(2) - SETTERMID command failedSub RuleAccess FailureCommand Execution Failure
Solaris auditon(2) - SESTATE command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETALL command failedSub RuleAccess FailureCommand Execution Failure
Solaris msgctl(2) - IPC_RMID command failedSub RuleAccess FailureCommand Execution Failure
Solaris facl(2) - SETACL command failedSub RuleAccess FailureCommand Execution Failure
Solaris execve(2) failedSub RuleAccess FailureCommand Execution Failure
Solaris exec(2) failedSub RuleAccess FailureCommand Execution Failure
Solaris enter prom failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - IPC_STAT command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - IPC_RMID command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETZCNT command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETVAL command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETPID command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETNCNT command failedSub RuleAccess FailureCommand Execution Failure
Solaris setauid(2) okSub RuleConfigurationConfiguration Modified : Security
Solaris setaudit_addr(2) okSub RuleConfigurationConfiguration Modified : Security
Solaris setaudit(2) okSub RuleConfigurationConfiguration Modified : Security
Solaris add user/user attributes okSub RuleConfigurationConfiguration Modified : Security
Solaris setppriv(2) okSub RulePolicyPolicy Enabled : System
Solaris modctl(2) - configure device policy okSub RulePolicyPolicy Enabled : System
Solaris modctl(2) - configure addit priv okSub RulePolicyPolicy Enabled : System
Solaris acct(2) okSub RulePolicyPolicy Enabled : System
Solaris at-permission okSub RulePolicyPolicy Enabled : Object
Solaris socket(2) okSub RuleInformationCommunication Endpoint Created
Solaris allocate-list devices failure failedSub RuleErrorFailed Device Allocation
Solaris allocate-device failure failedSub RuleErrorFailed Device Allocation
Solaris auditsvc(2) failedSub RuleOther Audit FailureFailed Audit Log Write
Solaris getmsg-accept failedSub RuleErrorFailed To Accept Message
Solaris modctl(2) - bind module failedSub RuleErrorFailed Module Bind
Solaris modctl(2) - unload module failedSub RuleWarningFailed Module Unload
Solaris msggetl(2) failedSub RuleErrorFailed Message Queue Retrieval
Solaris msgget(2) failedSub RuleErrorFailed Message Queue Retrieval
Solaris sendto(2) failedSub RuleErrorFailed Message Sending Operation
Solaris sendmsg(2) failedSub RuleErrorFailed Message Sending Operation
Solaris send(2) failedSub RuleErrorFailed Message Sending Operation
Solaris putpmsg(2) failedSub RuleErrorFailed Message Sending Operation
Solaris putmsg-send failedSub RuleErrorFailed Message Sending Operation
Solaris putmsg-connect failedSub RuleErrorFailed Message Sending Operation
Solaris putmsg(2) failedSub RuleErrorFailed Message Sending Operation
Solaris msgsndl(2) failedSub RuleErrorFailed Message Sending Operation
Solaris msgsnd(2) failedSub RuleErrorFailed Message Sending Operation
Solaris quotactl(2) failedSub RuleErrorFailed Disk Quotas Change
Solaris recvmsg(2) failedSub RuleWarningFailed to Receive Message
Solaris recvfrom(2) failedSub RuleWarningFailed to Receive Message
Solaris recv(2) failedSub RuleWarningFailed to Receive Message
Solaris semop(2) failedSub RuleErrorFailed Semaphore Operation
Solaris smserverd failedSub RuleErrorFailed Service Start
Solaris socketpair(2) failedSub RuleWarningFailed Pair of Connected Sockets Created
Solaris doorfs(2) - DOOR_UNBIND okSub RuleOther Audit SuccessThread Unbound From Server Pool
Solaris nfs_svc(2) okSub RuleStartup and ShutdownProcess/Service Started
Solaris nfs server okSub RuleStartup and ShutdownProcess/Service Started
Solaris vfork(2) okSub RuleStartup and ShutdownProcess/Service Started
Solaris system booted okSub RuleStartup and ShutdownProcess/Service Started
Solaris smserverd okSub RuleStartup and ShutdownProcess/Service Started
Solaris fork1(2) okSub RuleStartup and ShutdownProcess/Service Started
Solaris fork(2) okSub RuleStartup and ShutdownProcess/Service Started
Solaris getmsg-accept okSub RuleOther Audit SuccessMessage Accepted
Solaris modctl(2) - bind module okSub RuleOther Audit SuccessModule Bound
Solaris modctl(2) - no longer generated okSub RuleOther Audit SuccessModule Completed
Solaris semctl(2) - IPC_SET command okSub RuleOther Audit SuccessMemory Segment Assigned
Solaris msgctl(2) - IPC_SET command okSub RuleOther Audit SuccessMemory Segment Assigned
Solaris rexecd okSub RuleOther Audit SuccessGeneral Audit
Solaris rexd okSub RuleOther Audit SuccessGeneral Audit
Solaris process dumped core okSub RuleOther Audit SuccessGeneral Audit
Solaris priocntlsys(2) okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_RETURN okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_INFO okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_CRED okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_CREATE okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_CALL okSub RuleOther Audit SuccessGeneral Audit
Solaris authorization used okSub RuleOther Audit SuccessGeneral Audit
Solaris inetd copylimit okSub RuleOther Audit SuccessGeneral Audit
Solaris inetd connect okSub RuleOther Audit SuccessGeneral Audit
Solaris vtrace(2) okSub RuleOther Audit SuccessGeneral Audit
Solaris utssys(2) - fusers okSub RuleOther Audit SuccessGeneral Audit
Solaris exportfs(2) okSub RuleOther Audit SuccessGeneral Audit
Solaris doorfs(2) - DOOR_REVOKE okSub RuleOther Audit SuccessGeneral Audit
Solaris one-sided session record okSub RuleOther Audit SuccessGeneral Audit
Solaris kernel cryptographic framework okSub RuleOther Audit SuccessGeneral Audit
Solaris logout okSub RuleAuthentication SuccessUser Logoff
Solaris ftp logout okSub RuleAuthentication SuccessUser Logoff
Solaris statvfs(2) failedSub RuleAccess FailureRead Object Failure
Solaris statfs(2) failedSub RuleAccess FailureRead Object Failure
Solaris shmgetl(2) failedSub RuleAccess FailureRead Object Failure
Solaris shmget(2) failedSub RuleAccess FailureRead Object Failure
Solaris stat(2) failedSub RuleAccess FailureRead Object Failure
Solaris lxstat(2) failedSub RuleAccess FailureRead Object Failure
Solaris fstatfs(2) failedSub RuleAccess FailureRead Object Failure
Solaris fstatat(2) failedSub RuleAccess FailureRead Object Failure
Solaris fstat(2) failedSub RuleAccess FailureRead Object Failure
Solaris fcntl(2) failedSub RuleAccess FailureRead Object Failure
Solaris lstat(2) failedSub RuleAccess FailureRead Object Failure
Solaris lseek(2) failedSub RuleAccess FailureRead Object Failure
Solaris getmsg(2) failedSub RuleAccess FailureRead Object Failure
Solaris getauid(2) failedSub RuleAccess FailureRead Object Failure
Solaris getaudit_addr(2) failedSub RuleAccess FailureRead Object Failure
Solaris getaudit(2) failedSub RuleAccess FailureRead Object Failure
Solaris delete scheduled job okSub RuleConfigurationConfiguration Deleted : System
Solaris crontab-crontab deleted okSub RuleConfigurationConfiguration Deleted : System
Solaris at-delete atjob (at or atrm) okSub RuleConfigurationConfiguration Deleted : System
Solaris facl(2) - SETACL command okSub RulePolicyPolicy Enabled : Firewall/ACL
Solaris acl(2) - SETACL command okSub RulePolicyPolicy Enabled : Firewall/ACL
Solaris setuseraudit(2) okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - SETTERMID command okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set queue cntrl param okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set mask per session ID okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set mask per audit uid okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set kernel mask okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set event class okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set audit state okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - set audit policy flags okSub RulePolicyPolicy Enabled : Auditing
Solaris auditon(2) - SESTATE command okSub RulePolicyPolicy Enabled : Auditing
Solaris unmount(2) okSub RuleAccess SuccessObject Closed
Solaris unmount okSub RuleAccess SuccessObject Closed
Solaris unlinkat(2) okSub RuleAccess SuccessObject Closed
Solaris unlink(2) okSub RuleAccess SuccessObject Closed
Solaris umount2(2) okSub RuleAccess SuccessObject Closed
Solaris close(2) okSub RuleAccess SuccessObject Closed
Solaris mknod(2) okSub RuleAccess SuccessObject Created
Solaris mkdir(2) okSub RuleAccess SuccessObject Created
Solaris xmknod(2) okSub RuleAccess SuccessObject Created
Solaris symlink(2) okSub RuleAccess SuccessObject Created
Solaris creat(2) okSub RuleAccess SuccessObject Created
Solaris init(1m) failedSub RuleWarningFailed Process Control Initialization
Solaris fork1(2) failedSub RuleErrorFailed Process Creation
Solaris fork(2) failedSub RuleErrorFailed Process Creation
Solaris exit(2) failedSub RuleErrorFailed Process Termination
Solaris exit prom failedSub RuleErrorFailed Process Termination
Solaris adjtime(2) failedSub RuleWarningFailed Time Synchronization
Solaris bind(2) failedSub RuleOther Audit FailureFailed Configuration
Solaris msgctl(2) - illegal command failedSub RuleErrorFailed File System Mount
Solaris mount(2) failedSub RuleErrorFailed File System Mount
Solaris mount failedSub RuleErrorFailed File System Mount
Solaris screenlock - lock okSub RuleOther AuditScreen Locked
Solaris pathconf(2) okSub RuleAccess SuccessObject Accessed
Solaris msggetl(2) okSub RuleAccess SuccessObject Accessed
Solaris msgget(2) okSub RuleAccess SuccessObject Accessed
Solaris lxstat(2) okSub RuleAccess SuccessObject Accessed
Solaris lstat(2) okSub RuleAccess SuccessObject Accessed
Solaris getpmsg(2) okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get audit policy flags okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - GESTATE command okSub RuleAccess SuccessObject Accessed
Solaris access(2) okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get kernel mask okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get event class okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get curr working dir okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get current active root okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get audit statistics okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get audit state okSub RuleAccess SuccessObject Accessed
Solaris shmget(2) okSub RuleAccess SuccessObject Accessed
Solaris fstatfs(2) okSub RuleAccess SuccessObject Accessed
Solaris fstatat(2) okSub RuleAccess SuccessObject Accessed
Solaris fstat(2) okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - GETTERMID command okSub RuleAccess SuccessObject Accessed
Solaris auditon(2) - get queue cntrl param okSub RuleAccess SuccessObject Accessed
Solaris getmsg(2) okSub RuleAccess SuccessObject Accessed
Solaris getaudit_addr(2) okSub RuleAccess SuccessObject Accessed
Solaris statvfs(2) okSub RuleAccess SuccessObject Accessed
Solaris statfs(2) okSub RuleAccess SuccessObject Accessed
Solaris stat(2) okSub RuleAccess SuccessObject Accessed
Solaris shmgetl(2) okSub RuleAccess SuccessObject Accessed
Solaris seteuid(2) okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris profile command okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris setuid(2) okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris modify user/user attributes okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris modify user okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris setreuid(2) okSub RuleAccount ModifiedUser Account Attribute Modified
Solaris passwd okSub RuleAccount ModifiedPassword Modified
Solaris passwd failedSub RuleOther Audit FailureFailed Password Change Attempt
Solaris allocate-list devices success okSub RuleOther Audit SuccessDevice Allocated
Solaris allocate-device success okSub RuleOther Audit SuccessDevice Allocated
Solaris fcntl(2) okSub RuleOther Audit SuccessFile Control Operation
Solaris dup2(2) okSub RuleOther Audit SuccessFile Descriptor Duplicated
Solaris auditon(2) - reset audit statistics okSub RuleOther Audit SuccessAudit Statistics Reset
Solaris utime(2) okSub RuleOther AuditFile Modification Times Set
Solaris semctl(2) - illegal command failedSub RuleFailed SuspiciousFailed Suspicious Host Activity
Solaris junk okSub RuleOther Audit SuccessGeneral Audit
Solaris inst_sync(2) okSub RuleOther Audit SuccessGeneral Audit
Solaris inetd ratelimit okSub RuleOther Audit SuccessGeneral Audit
Solaris inetd failrate okSub RuleOther Audit SuccessGeneral Audit
Solaris delete user/user attributes okSub RuleAccount DeletedUser Account Deleted
Solaris delete user okSub RuleAccount DeletedUser Account Deleted
Solaris shutdown(2) okSub RuleStartup and ShutdownSystem Shutdown
Solaris shutdown(1b) okSub RuleStartup and ShutdownSystem Shutdown
Solaris poweroff(1m) okSub RuleStartup and ShutdownSystem Shutting Down
Solaris halt(1m) okSub RuleStartup and ShutdownSystem Shutting Down
Solaris lseek(2) okSub RuleOther Audit SuccessFile Pointer Operation
Solaris memcntl(2) okSub RuleOther Audit SuccessMemory Management Operation
Solaris mctl(2) okSub RuleOther Audit SuccessMemory Management Operation
Solaris shmdt(2) okSub RuleOther Audit SuccessShared Memory Operation
Solaris shmctl(2) - IPC_STAT command okSub RuleOther Audit SuccessShared Memory Operation
Solaris shmctl(2) - IPC_SET command okSub RuleOther Audit SuccessShared Memory Operation
Solaris shmctl(2) - IPC_RMID command okSub RuleOther Audit SuccessShared Memory Operation
Solaris shmctl(2) - illegal command okSub RuleOther Audit SuccessShared Memory Operation
Solaris shmat(2) okSub RuleOther Audit SuccessShared Memory Operation
Solaris indir system call okSub RuleOther Audit SuccessSystem Call
Solaris clock_settime(3RT) okSub RuleOther Audit SuccessHigh Resolution Clock Operation
Solaris semctl(2) - IPC_SET command failedSub RuleErrorFailed To Assign Memory Segment
Solaris msgctl(2) - IPC_SET command failedSub RuleErrorFailed To Assign Memory Segment
Solaris pathconf(2) failedSub RuleErrorFailed Configurable Pathname Variables Retrieve
Solaris processor_bind(2) failedSub RuleErrorFailed Processes Bind
Solaris swapon(2) failedSub RuleErrorFailed Swap Space Added
Solaris system booted failedSub RuleErrorFailed System Boot
Solaris auditstat(2) okSub RuleOther Audit SuccessKernel Audit Statistics Displayed
Solaris deallocate-device success okSub RuleOther Audit SuccessDevice De-Allocated
Solaris exit(2) okSub RuleStartup and ShutdownProcess/Service Stopping
Solaris exit prom okSub RuleStartup and ShutdownProcess/Service Stopping
Solaris msgrcvl(2) okSub RuleOther Audit SuccessMessage Receiving Operation
Solaris msgrcv(2) okSub RuleOther Audit SuccessMessage Receiving Operation
Solaris msgsndl(2) okSub RuleOther Audit SuccessMessage Sending Operation
Solaris msgsnd(2) okSub RuleOther Audit SuccessMessage Sending Operation
Solaris accept(2) okSub RuleOther Audit SuccessPrint Request
Solaris vtrace(2) failedSub RuleErrorOther Audit Failure Message
Solaris utssys(2) - fusers failedSub RuleErrorOther Audit Failure Message
Solaris symlink(2) failedSub RuleErrorOther Audit Failure Message
Solaris rexecd failedSub RuleErrorOther Audit Failure Message
Solaris rexd failedSub RuleErrorOther Audit Failure Message
Solaris process dumped core failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_INFO failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_CRED failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_CREATE failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_CALL failedSub RuleErrorOther Audit Failure Message
Solaris authorization used failedSub RuleErrorOther Audit Failure Message
Solaris inetd failrate failedSub RuleErrorOther Audit Failure Message
Solaris inetd copylimit failedSub RuleErrorOther Audit Failure Message
Solaris inetd connect failedSub RuleErrorOther Audit Failure Message
Solaris exportfs(2) failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_REVOKE failedSub RuleErrorOther Audit Failure Message
Solaris doorfs(2) - DOOR_RETURN failedSub RuleErrorOther Audit Failure Message
Solaris priocntlsys(2) failedSub RuleErrorOther Audit Failure Message
Solaris one-sided session record failedSub RuleErrorOther Audit Failure Message
Solaris kernel cryptographic framework failedSub RuleErrorOther Audit Failure Message
Solaris junk failedSub RuleErrorOther Audit Failure Message
Solaris inst_sync(2) failedSub RuleErrorOther Audit Failure Message
Solaris inetd ratelimit failedSub RuleErrorOther Audit Failure Message
Solaris configure kernel SSL failedSub RuleWarningFailed Kernel SSL Configure
Solaris fchdir(2) failedSub RuleErrorFailed Change Working Directory
Solaris poweroff(1m) failedSub RuleErrorFailed Processor Stop
Solaris halt(1m) failedSub RuleErrorFailed Processor Stop
Solaris link(2) failedSub RuleWarningFailed File Link Creation
Solaris memcntl(2) failedSub RuleErrorFailed Memory Management Operation
Solaris mctl(2) failedSub RuleErrorFailed Memory Management Operation
Solaris mmap(2) failedSub RuleWarningFailed To Map Memory
Solaris msgrcvl(2) failedSub RuleErrorFailed Message Receiving Operation
Solaris msgrcv(2) failedSub RuleErrorFailed Message Receiving Operation
Solaris munmap(2) failedSub RuleErrorFailed Memory Unmap
Solaris nice(2) failedSub RuleWarningFailed Process Priority Change
Solaris reboot(2) failedSub RuleErrorFailed System Reboot
Solaris reboot(1m) failedSub RuleErrorFailed System Reboot
Solaris shutdown(2) failedSub RuleErrorFailed System Shut Down
Solaris shutdown(1b) failedSub RuleErrorFailed System Shut Down
Solaris vfork(2) failedSub RuleErrorFailed Process Start
Solaris doorfs(2) - DOOR_BIND okSub RuleOther Audit SuccessThread Bound To Server Pool
Solaris recvmsg(2) okSub RuleOther Audit SuccessMessage Received
Solaris recvfrom(2) okSub RuleOther Audit SuccessMessage Received
Solaris recv(2) okSub RuleOther Audit SuccessMessage Received
Solaris getmsg-receive okSub RuleOther Audit SuccessMessage Received
Solaris modctl(2) - load module okSub RuleOther Audit SuccessModule Loaded
Solaris processor_bind(2) okSub RuleOther Audit SuccessProcesses Bound
Solaris renameat(2) okSub RuleAccess SuccessObject Renamed
Solaris rename(2) okSub RuleAccess SuccessObject Renamed
Solaris unauthenticated kadmind req failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris su failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris screenlock - unlock failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris role login failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris logout failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris kdc tkt-grant svc request failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris kdc tgs issue alt tgt failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris kdc tgs 2ndtkt mismtch failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris kdc authentication svc request failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris ftp logout failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris authenticated kadmind request failedSub RuleAuthentication FailureAuthentication Failure Activity
Solaris create user okSub RuleAccount CreatedUser Account Created
Solaris chmod(2) okSub RuleAccess SuccessObject Attribute Modified
Solaris uadmin(1m) okSub RuleOther Audit SuccessAdministrative Operation
Solaris munmap(2) okSub RuleOther Audit SuccessMemory Unmapped
Solaris semop(2) okSub RuleOther Audit SuccessSemaphore Operation
Solaris killpg(2) okSub RuleAccess SuccessCommand Executed
Solaris kill(2) okSub RuleAccess SuccessCommand Executed
Solaris getauid(2) okSub RuleAccess SuccessCommand Executed
Solaris zoneadmd okSub RuleAccess SuccessCommand Executed
Solaris writevl(2) okSub RuleAccess SuccessCommand Executed
Solaris writev(2) okSub RuleAccess SuccessCommand Executed
Solaris enter prom okSub RuleAccess SuccessCommand Executed
Solaris cron-invoke okSub RuleAccess SuccessCommand Executed
Solaris chroot(2) okSub RuleAccess SuccessCommand Executed
Solaris chdir(2) okSub RuleAccess SuccessCommand Executed
Solaris auditsvc(2) okSub RuleAccess SuccessCommand Executed
Solaris audit(2) okSub RuleAccess SuccessCommand Executed
Solaris writel(2) okSub RuleAccess SuccessCommand Executed
Solaris write(2) okSub RuleAccess SuccessCommand Executed
Solaris fchroot(2) okSub RuleAccess SuccessCommand Executed
Solaris fchdir(2) okSub RuleAccess SuccessCommand Executed
Solaris execve(2) okSub RuleAccess SuccessCommand Executed
Solaris exec(2) okSub RuleAccess SuccessCommand Executed

Mapping of Catch All : Solaris 10 Audit with LR Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A

<vmid>

Text\String
N/A<sip>IP Address
from<sname>Text\String
N/A<login>Text\String
session<session>Number
N/A<tag1>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.