hit counter
   
 

Random ramblings of a paranoid git
"The question is not if you are paranoid, it is if you are paranoid enough."


All | Security | Work | Wine & Dine | Leisure

   
   
20040830 Monday August 30, 2004
AuditViewer
Permalink | Comments [1] | 2004-08-30 13:22

I spent the weekend rewriting the AuditViewer so I won't have to be ashamed of it, if I release it.

The basic mode of operation is to load an XML file (from "praudit -x"), and then scroll through the list of cronological audit records. Click on any record to get a detailed view of all the audit tokens of that record.

There is still a lot to be done. The cronological list needs to be filled with better information, the search function needs to me implemented, tooltips have to be added to describe the different fields.

If you have strong oppinions on what should be shown, feel free to speak up!

Here is an image, so you can get a feel for how it will look:

A few more days and I should have the basic things straightened out...

   
 
Comments:

Hi, It sure looks good and it is really welcomed !
The one thing I think would be really nice is a flexible search facility that would allow me to say something like "show all records between 29 Aug and 3 Sept 2004 for which the Audit UID is not "allowed_usr1" or "allowed_usr2" and real or effective uid is root".
Sort of subset of SQL adapted to BSM records . I realize this may not be so simple. But a few criteria would be good.
Great work !
Vlad.

Posted by Vlad Grama on August 30, 2004 at 02:06 PM PDT #

Post a Comment:

Comments are closed for this entry.
   
XML
« November 2009
SunMonTueWedThuFriSat
1
2
3
4
5
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
     
       
Today


Old entries


Bloggtoppen.se
OpenSolaris: Love at First Boot