How to restrain Audit log in vApp console
search cancel

How to restrain Audit log in vApp console

book

Article ID: 117360

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction



We see  many audit logs in vApp console and want to restrain them.
How do we configure vApp?

Oct 5 09:57:54 ServerA kernel: type = 1103 audit (1538701074.162: 2054): user pid = ##### uid = 0 auid = ##### voice = 4294967295 msg = 'op = PAM: setcred acct = usr / sbin / sshd "hostname = ServerA  addr = xxx.xxx.xxx.xxx terminal = ssh res = success' 
Oct 5 09:57:54 ServerA kernel: type = 1006 audit (1538701074.165: 2055): pid = ##### uid = 0 old auid = ##### new auid = 500 old sound = 4294967295 new voice = 62 

Environment

CA Identity Suite Virtual Appliance r14.x
 

Resolution

  • Run following command for checking status of audit log.   
         audit_show
  • Run following command for disabling Audit log.

         audit_disable

  • Run following command for enabling Audit log.

         audit_enable