Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

System audit software for Solaris ?

Thread Tools
 
Search this Thread
 
Old 17 December 2002, 02:14 PM
  #1  
druddle
Scooby Regular
Thread Starter
 
druddle's Avatar
 
Join Date: Mar 2001
Location: Berkshire
Posts: 5,528
Likes: 0
Received 0 Likes on 0 Posts
Question

Does anyone know of any audit-type software for Solaris ? I am after something that can do things like check for changes to files, estate-wide updates to files, sort of like MS SMS but for Solaris ?

Cheers

Dave
Old 17 December 2002, 02:28 PM
  #2  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Arrow

Pentasafe do one, we use it on Solaris and AS400

http://www.pentasafe.com/
Old 17 December 2002, 03:37 PM
  #3  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Arrow

PS. its called Vigilent
Old 17 December 2002, 04:33 PM
  #4  
krankyd
Scooby Regular
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

TRIPWIRE.


Burn a copy of the output onto a cdrom, place cdrom in drive, run tripwire every night

Old 17 December 2002, 05:28 PM
  #5  
druddle
Scooby Regular
Thread Starter
 
druddle's Avatar
 
Join Date: Mar 2001
Location: Berkshire
Posts: 5,528
Likes: 0
Received 0 Likes on 0 Posts
Post

dave - does Tripwire put much load on the servers, as it seems to want to log all I/O and compare it against a database ??

Dave
Old 17 December 2002, 06:14 PM
  #6  
orbv
Scooby Regular
 
orbv's Avatar
 
Join Date: Apr 2001
Location: Hants
Posts: 1,103
Likes: 0
Received 0 Likes on 0 Posts
Post

why not use the built in stuff?

Check out here
Old 17 December 2002, 11:22 PM
  #7  
orbv
Scooby Regular
 
orbv's Avatar
 
Join Date: Apr 2001
Location: Hants
Posts: 1,103
Likes: 0
Received 0 Likes on 0 Posts
Post

or maybe this doc will help here
Old 18 December 2002, 09:59 AM
  #8  
krankyd
Scooby Regular
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

Sorry for the long reply - been out on the champagane last night

Shouldn't put too much of a load on the server. The real load is when you run it for the first time to get a list of all the current files and permissions..

It's only like doing a ls -laR and comparing the output with a flat-file. Just don't expect it to run very fast on a Ultra 10

Should be alright though - I'll install it tonight or over the weekend on a couple of boxes and see how quick it is...

My bets is the blade 100 will be v.slow, but my server farm of 6800's will be a bit quicker

Old 18 December 2002, 10:10 AM
  #9  
druddle
Scooby Regular
Thread Starter
 
druddle's Avatar
 
Join Date: Mar 2001
Location: Berkshire
Posts: 5,528
Likes: 0
Received 0 Likes on 0 Posts
Post

Cheers dave, let me know how you get on.

It will be going on Primepower 650/2000 and the brand new 2500s with loads of horsepower

Dave
Old 18 December 2002, 11:22 AM
  #10  
krankyd
Scooby Regular
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

If you're looking for more of a network-based thing, I've seed IDS used previously and it works really well.

It used heuirestics to monitor the network traffic and trends for a while. Then when it sees a new `attack` that is not part of normal operation it blocks it and flags an alert. Really cool if you like geeky things like me

Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
hardcoreimpreza
Computer & Technology Related
21
11 October 2015 03:40 PM
crazyspeedfreakz
Wanted
17
05 October 2015 07:19 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM
sedge69
Wanted
0
01 October 2015 09:44 PM



Quick Reply: System audit software for Solaris ?



All times are GMT +1. The time now is 01:32 AM.