Skip to main content
Skip table of contents

Pattern 5 : Solaris 10 Object Access

Classification

Rule Name

Rule Type

Classification

Common Event

Pattern 5 : Solaris 10 Object AccessBase RuleOther Audit SuccessGeneral Audit
Solaris unmount(2) okSub RuleAccess SuccessObject Closed
Solaris unmount okSub RuleAccess SuccessObject Closed
Solaris unlinkat(2) okSub RuleAccess SuccessObject Closed
Solaris unlink(2) okSub RuleAccess SuccessObject Closed
Solaris umount2(2) okSub RuleAccess SuccessObject Closed
Solaris close(2) okSub RuleAccess SuccessObject Closed
Solaris mknod(2) okSub RuleAccess SuccessObject Created
Solaris xmknod(2) okSub RuleAccess SuccessObject Created
Solaris symlink(2) okSub RuleAccess SuccessObject Created
Solaris creat(2) okSub RuleAccess SuccessObject Created
Solaris renameat(2) okSub RuleAccess SuccessObject Renamed
Solaris rename(2) okSub RuleAccess SuccessObject Renamed
Solaris writevl(2) okSub RuleAccess SuccessCommand Executed
Solaris writev(2) okSub RuleAccess SuccessCommand Executed
Solaris writel(2) okSub RuleAccess SuccessCommand Executed
Solaris write(2) okSub RuleAccess SuccessCommand Executed
Solaris execve(2) okSub RuleAccess SuccessCommand Executed
Solaris exec(2) okSub RuleAccess SuccessCommand Executed
Solaris General Successful AccessSub RuleAccess SuccessObject Accessed
Solaris semgetl(2) okSub RuleAccess SuccessObject Read
Solaris semget(2) okSub RuleAccess SuccessObject Read
Solaris semctl(2) - IPC_STAT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETZCNT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETVAL command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETPID command okSub RuleAccess SuccessObject Read
Solaris getportaudit(2) okSub RuleAccess SuccessObject Read
Solaris getkernstate(2) okSub RuleAccess SuccessObject Read
Solaris getdents(2) okSub RuleAccess SuccessObject Read
Solaris xstat(2) okSub RuleAccess SuccessObject Read
Solaris sysinfo(2) okSub RuleAccess SuccessObject Read
Solaris open(2) - read,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - read okSub RuleAccess SuccessObject Read
Solaris nfs_getfh(2) okSub RuleAccess SuccessObject Read
Solaris msgctl(2) - IPC_STAT command okSub RuleAccess SuccessObject Read
Solaris ioctl(2) okSub RuleAccess SuccessObject Read
Solaris getuseraudit(2) okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - read,write okSub RuleAccess SuccessObject Read
Solaris open(2) - read,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - read,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - read okSub RuleAccess SuccessObject Read
Solaris open(2) - write,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris open(2) - write,creat okSub RuleAccess SuccessObject Read
Solaris open(2) - write okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,write okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - read,creat,trunc okSub RuleAccess SuccessObject Read
Solaris read(2) okSub RuleAccess SuccessObject Read
Solaris p_online(2) okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,creat,trunc okSub RuleAccess SuccessObject Read
Solaris openat(2) - write,creat okSub RuleAccess SuccessObject Read
Solaris openat(2) - write okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETNCNT command okSub RuleAccess SuccessObject Read
Solaris semctl(2) - GETALL command okSub RuleAccess SuccessObject Read
Solaris readvl(2) okSub RuleAccess SuccessObject Read
Solaris readv(2) okSub RuleAccess SuccessObject Read
Solaris readlink(2) okSub RuleAccess SuccessObject Read
Solaris readl(2) okSub RuleAccess SuccessObject Read
Solaris rmdir(2) okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete serial port okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete printer okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete network attributes okSub RuleAccess SuccessObject Deleted/Removed
Solaris delete filesystem okSub RuleAccess SuccessObject Deleted/Removed
Solaris rmdir(2) failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete serial port failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete printer failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete network attributes failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris delete filesystem failedSub RuleAccess FailureDelete/Remove Object Failure
Solaris socket(2) failedSub RuleAccess FailureCreate Object Failure
Solaris fchownat(2) failedSub RuleAccess FailureModify Object Failure
Solaris fchown(2) failedSub RuleAccess FailureModify Object Failure
Solaris writevl(2) failedSub RuleAccess FailureModify Object Failure
Solaris writev(2) failedSub RuleAccess FailureModify Object Failure
Solaris writel(2) failedSub RuleAccess FailureModify Object Failure
Solaris write(2) failedSub RuleAccess FailureModify Object Failure
Solaris unmount(2) failedSub RuleAccess FailureClose Object Failure
Solaris unmount failedSub RuleAccess FailureClose Object Failure
Solaris unlinkat(2) failedSub RuleAccess FailureClose Object Failure
Solaris unlink(2) failedSub RuleAccess FailureClose Object Failure
Solaris umount2(2) failedSub RuleAccess FailureClose Object Failure
Solaris close(2) failedSub RuleAccess FailureClose Object Failure
Solaris xstat(2) failedSub RuleAccess FailureAccess Object Failure
Solaris sysinfo(2) failedSub RuleAccess FailureAccess Object Failure
Solaris semgetl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris semget(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readvl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readv(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getuseraudit(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getportaudit(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getkernstate(2) failedSub RuleAccess FailureAccess Object Failure
Solaris getdents(2) failedSub RuleAccess FailureAccess Object Failure
Solaris auditstat(2) failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read failedSub RuleAccess FailureAccess Object Failure
Solaris nfs_getfh(2) failedSub RuleAccess FailureAccess Object Failure
Solaris ioctl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - read,write failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris open(2) - write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write,creat failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - read,write failedSub RuleAccess FailureAccess Object Failure
Solaris readlink(2) failedSub RuleAccess FailureAccess Object Failure
Solaris readl(2) failedSub RuleAccess FailureAccess Object Failure
Solaris read(2) failedSub RuleAccess FailureAccess Object Failure
Solaris p_online(2) failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris openat(2) - write,creat,trunc failedSub RuleAccess FailureAccess Object Failure
Solaris renameat(2) failedSub RuleAccess FailureRename Object Failure
Solaris rename(2) failedSub RuleAccess FailureRename Object Failure
Solaris semctl(2) - IPC_STAT command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETZCNT command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETVAL command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETPID command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETNCNT command failedSub RuleAccess FailureCommand Execution Failure
Solaris semctl(2) - GETALL command failedSub RuleAccess FailureCommand Execution Failure
Solaris msgctl(2) - IPC_STAT command failedSub RuleAccess FailureCommand Execution Failure
Solaris execve(2) failedSub RuleAccess FailureCommand Execution Failure
Solaris exec(2) failedSub RuleAccess FailureCommand Execution Failure
Solaris fchownat(2) okSub RulePolicyPolicy Modified : Object
Solaris fchown(2) okSub RulePolicyPolicy Modified : Object

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<vmid>Number
N/A<sip>Number
N/A<sname>Text\String
N/A

<login>

Text\String
N/A<session>Text\String
N/A<object>Text\String
N/A<tag1>Text\String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.