On 29 juin 2011, at 12:59, Lev Serebryakov wrote:

>  auditreduce doesn't filter events by date (-b/-a/-d options with any
> arguments produces empty output), it doesn't merge files properly and
> doesn't pick up files automagically, as Solaris' one does. It doesn't
> have -C/-M/-O functionality of Solaris' one, too. So, proper merging
> of audit trial files seems to be impossible :(
> 
>  I could try to fix & extend auditreduce(1), but does somebdy but me
> need it?
> 
>  Does somebody use audit on FreeBSD on production systems?

I do, almost (I've not finished my settup, but I'm auditing a production 
server).
May be you'll find this interesting: 
http://forums.freebsd.org/showthread.php?t=23716#9

patpro

Reply via email to