From owner-freebsd-questions@FreeBSD.ORG Sat May 9 17:32:00 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 9B5B01065675 for ; Sat, 9 May 2009 17:32:00 +0000 (UTC) (envelope-from river@loreley.flyingparchment.org.uk) Received: from loreley.flyingparchment.org.uk (cl-121.lon-02.gb.sixxs.net [IPv6:2a01:348:6:78::2]) by mx1.freebsd.org (Postfix) with ESMTP id D6EB98FC12 for ; Sat, 9 May 2009 17:31:59 +0000 (UTC) (envelope-from river@loreley.flyingparchment.org.uk) Received: from loreley.flyingparchment.org.uk (river@localhost [127.0.0.1]) by loreley.flyingparchment.org.uk (@(#)Sendmail version 8.13.3 - Revision 1.005 - 15 November 2007/8.13.3) with ESMTP id n49HVv3H010988 for ; Sat, 9 May 2009 18:31:57 +0100 (BST) Received: (from river@localhost) by loreley.flyingparchment.org.uk (@(#)Sendmail version 8.13.3 - Revision 1.005 - 15 November 2007/8.13.3/Submit) id n49HVvWk010987 for freebsd-questions@freebsd.org; Sat, 9 May 2009 18:31:57 +0100 (BST) Date: Sat, 9 May 2009 18:31:57 +0100 From: River Tarnell To: freebsd-questions@freebsd.org Message-ID: <20090509173157.GO17743@loreley.flyingparchment.org.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; x-action=pgp-signed Content-Disposition: inline User-Agent: Mutt/1.5.19 (2009-01-05) Subject: connect() records in BSM auditing X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 09 May 2009 17:32:01 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 hi, i'm using BSM auditing on 7.2-RELEASE to log network connections. i enabled 'nt' in audit_control: flags:lo,ad,+ex,na,+nt when examining the audit log with praudit, i see records for connect() calls: header,68,10,connect(2),0,Sat May 9 16:00:00 2009, + 560 msec subject,rriver,root,wheel,root,wheel,43709,835,15007,255.255.255.255 return,success,0 trailer,68 however, i don't see that the destination (or source) address is logged anywhere. i don't really see the point of auditing network activity without this information--is this a missing feature, or have i misconfigured something? thanks, river. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (HP-UX) iEYEARECAAYFAkoFvg0ACgkQIXd7fCuc5vKRFACeJaVKeRBe9OUyPU/j9HrfBVMw XYQAoIR7CAb/SqujCg1QIFUoVRFhyGnD =M1bm -----END PGP SIGNATURE-----