2 # Copyright (c) 1992, 2010, Oracle and/or its affiliates. All rights reserved.
7 # The contents of this file are subject to the terms of the
8 # Common Development and Distribution License (the "License").
9 # You may not use this file except in compliance with the License.
11 # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
12 # or http://www.opensolaris.org/os/licensing.
13 # See the License for the specific language governing permissions
14 # and limitations under the License.
16 # When distributing Covered Code, include this CDDL HEADER in each
17 # file and include the License file at usr/src/OPENSOLARIS.LICENSE.
18 # If applicable, add the following below this CDDL HEADER, with the
19 # fields enclosed by brackets "[]" replaced with your own identifying
20 # information: Portions Copyright [yyyy] [name of copyright owner]
24 # Audit Event Database
28 # event number:event name:event description:event classes (comma separated)
30 # Used to map audit events to audit classes for preselection and post-selection.
31 # Used by TCB programs that write audit records to preselect audit events
32 # based on event to class mappings.
34 # NOTE: several events are obsolete but must continue to be defined here for
35 # compatibility reasons. Obsolete events are defined in the "no" (invalid)
36 # class to indicate they will not be generated. Other events in the "no"
37 # class which are not obsolete (but are in this class for other reasons),
38 # are individually noted with a comment for explanation.
40 # System Adminstrators: Do NOT modify or add events with an event number less
41 # than 32768. These are reserved by the system.
43 # 0 Reserved as an invalid event number.
44 # 1 - 2047 Reserved for the Solaris Kernel events.
45 # 2048 - 32767 Reserved for the Solaris TCB programs.
46 # 32768 - 65535 Available for third party TCB applications.
49 # Allocation of reserved kernel events:
50 # (NOTE: the kernel event table, and possibly MAX_KEVENTS, must be updated
51 # in audit_kevents.h when changes are made to kernel events.)
52 # 1 - 511 allocated for Solaris
53 # 512 - 2047 (reserved but not allocated)
55 # Allocation of user level audit events:
56 # 2048 - 5999 (reserved but not allocated)
57 # 6000 - 9999 allocated for Solaris
58 # 10000 - 32767 (reserved but not allocated)
59 # 32768 - 65535 (Available for third party TCB applications)
63 # 1 - 511 allocated for Solaris
65 0:AUE_NULL:indir system call:no
67 2:AUE_FORKALL:forkall(2):ps
68 # AUE_OPEN is a placeholder and will not be generated
69 3:AUE_OPEN:open(2) - place holder:no
70 4:AUE_CREAT:creat(2):no
72 6:AUE_UNLINK:unlink(2):fd
74 8:AUE_CHDIR:chdir(2):pm
75 9:AUE_MKNOD:mknod(2):fc
76 10:AUE_CHMOD:chmod(2):fm
77 11:AUE_CHOWN:chown(2):fm
78 12:AUE_UMOUNT:umount(2) - old version:as
80 14:AUE_ACCESS:access(2):fa
81 15:AUE_KILL:kill(2):pm
82 16:AUE_STAT:stat(2):fa
83 17:AUE_LSTAT:lstat(2):fa
84 18:AUE_ACCT:acct(2):as
85 19:AUE_MCTL:mctl(2):no
86 20:AUE_REBOOT:reboot(2):no
87 21:AUE_SYMLINK:symlink(2):fc
88 22:AUE_READLINK:readlink(2):fr
89 23:AUE_EXECVE:execve(2):ps,ex
90 24:AUE_CHROOT:chroot(2):pm
91 25:AUE_VFORK:vfork(2):ps
92 26:AUE_SETGROUPS:setgroups(2):pm
93 27:AUE_SETPGRP:setpgrp(2):pm
94 28:AUE_SWAPON:swapon(2):no
95 29:AUE_SETHOSTNAME:sethostname(2):no
96 30:AUE_FCNTL:fcntl(2):fm
97 31:AUE_SETPRIORITY:setpriority(2):no
98 32:AUE_CONNECT:connect(2):nt
99 33:AUE_ACCEPT:accept(2):nt
100 34:AUE_BIND:bind(2):nt
101 35:AUE_SETSOCKOPT:setsockopt(2):nt
102 36:AUE_VTRACE:vtrace(2):no
103 37:AUE_SETTIMEOFDAY:settimeofday(2):no
104 38:AUE_FCHOWN:fchown(2):fm
105 39:AUE_FCHMOD:fchmod(2):fm
106 40:AUE_SETREUID:setreuid(2):pm
107 41:AUE_SETREGID:setregid(2):pm
108 42:AUE_RENAME:rename(2):fc,fd
109 43:AUE_TRUNCATE:truncate(2):no
110 44:AUE_FTRUNCATE:ftruncate(2):no
111 45:AUE_FLOCK:flock(2):no
112 46:AUE_SHUTDOWN:shutdown(2):nt
113 47:AUE_MKDIR:mkdir(2):fc
114 48:AUE_RMDIR:rmdir(2):fd
115 49:AUE_UTIMES:utimes(2):fm
116 50:AUE_ADJTIME:adjtime(2):as
117 51:AUE_SETRLIMIT:setrlimit(2):ua
118 52:AUE_KILLPG:killpg(2):no
119 53:AUE_NFS_SVC:nfs_svc(2):no
120 54:AUE_STATFS:statfs(2):fa
121 55:AUE_FSTATFS:fstatfs(2):fa
122 56:AUE_UNMOUNT:unmount(2):no
123 57:AUE_ASYNC_DAEMON:async_daemon(2):no
124 58:AUE_NFS_GETFH:nfs_getfh(2):no
125 59:AUE_SETDOMAINNAME:setdomainname(2):no
126 60:AUE_QUOTACTL:quotactl(2):no
127 61:AUE_EXPORTFS:exportfs(2):no
128 62:AUE_MOUNT:mount(2):as
129 # AUE_SEMSYS is a placeholder and will not be generated
130 63:AUE_SEMSYS:semsys(2) - place holder:no
131 # AUE_MSGSYS is a placeholder and will not be generated
132 64:AUE_MSGSYS:msgsys(2) - place holder:no
133 # AUE_SHMSYS is a placeholder and will not be generated
134 65:AUE_SHMSYS:shmsys(2) - place holder:no
135 66:AUE_BSMSYS:bsmsys(2) - place holder:no
136 67:AUE_RFSSYS:rfssys(2) - place holder:no
137 68:AUE_FCHDIR:fchdir(2):pm
138 69:AUE_FCHROOT:fchroot(2):pm
139 70:AUE_VPIXSYS:vpixsys(2) - place holder:no
140 71:AUE_PATHCONF:pathconf(2):fa
141 72:AUE_OPEN_R:open(2) - read:fr
142 73:AUE_OPEN_RC:open(2) - read,creat:fc,fr
143 74:AUE_OPEN_RT:open(2) - read,trunc:fd,fr
144 75:AUE_OPEN_RTC:open(2) - read,creat,trunc:fc,fd,fr
145 76:AUE_OPEN_W:open(2) - write:fw
146 77:AUE_OPEN_WC:open(2) - write,creat:fc,fw
147 78:AUE_OPEN_WT:open(2) - write,trunc:fd,fw
148 79:AUE_OPEN_WTC:open(2) - write,creat,trunc:fc,fd,fw
149 80:AUE_OPEN_RW:open(2) - read,write:fr,fw
150 81:AUE_OPEN_RWC:open(2) - read,write,creat:fc,fw,fr
151 82:AUE_OPEN_RWT:open(2) - read,write,trunc:fd,fr,fw
152 83:AUE_OPEN_RWTC:open(2) - read,write,creat,trunc:fc,fd,fw,fr
153 84:AUE_MSGCTL:msgctl(2) - illegal command:ip
154 85:AUE_MSGCTL_RMID:msgctl(2) - IPC_RMID command:ip
155 86:AUE_MSGCTL_SET:msgctl(2) - IPC_SET command:ip
156 87:AUE_MSGCTL_STAT:msgctl(2) - IPC_STAT command:ip
157 88:AUE_MSGGET:msgget(2):ip
158 89:AUE_MSGRCV:msgrcv(2):ip
159 90:AUE_MSGSND:msgsnd(2):ip
160 91:AUE_SHMCTL:shmctl(2) - illegal command:ip
161 92:AUE_SHMCTL_RMID:shmctl(2) - IPC_RMID command:ip
162 93:AUE_SHMCTL_SET:shmctl(2) - IPC_SET command:ip
163 94:AUE_SHMCTL_STAT:shmctl(2) - IPC_STAT command:ip
164 95:AUE_SHMGET:shmget(2):ip
165 96:AUE_SHMAT:shmat(2):ip
166 97:AUE_SHMDT:shmdt(2):ip
167 98:AUE_SEMCTL:semctl(2) - illegal command:ip
168 99:AUE_SEMCTL_RMID:semctl(2) - IPC_RMID command:ip
169 100:AUE_SEMCTL_SET:semctl(2) - IPC_SET command:ip
170 101:AUE_SEMCTL_STAT:semctl(2) - IPC_STAT command:ip
171 102:AUE_SEMCTL_GETNCNT:semctl(2) - GETNCNT command:ip
172 103:AUE_SEMCTL_GETPID:semctl(2) - GETPID command:ip
173 104:AUE_SEMCTL_GETVAL:semctl(2) - GETVAL command:ip
174 105:AUE_SEMCTL_GETALL:semctl(2) - GETALL command:ip
175 106:AUE_SEMCTL_GETZCNT:semctl(2) - GETZCNT command:ip
176 107:AUE_SEMCTL_SETVAL:semctl(2) - SETVAL command:ip
177 108:AUE_SEMCTL_SETALL:semctl(2) - SETALL command:ip
178 109:AUE_SEMGET:semget(2):ip
179 110:AUE_SEMOP:semop(2):ip
180 111:AUE_CORE:process dumped core:fc
181 112:AUE_CLOSE:close(2):cl
182 113:AUE_SYSTEMBOOT:system booted:na
183 114:AUE_ASYNC_DAEMON_EXIT:async_daemon(2) exited:no
184 115:AUE_NFSSVC_EXIT:nfssvc(2) exited:no
185 116:AUE_PFEXEC:execve(2) with pfexec enabled:ps,ex,ua,as
186 117:AUE_OPEN_S:open(2) - search:fr
187 118:AUE_OPEN_E:open(2) - exec:fr
189 130:AUE_GETAUID:getauid(2):aa
190 131:AUE_SETAUID:setauid(2):aa
191 132:AUE_GETAUDIT:getaudit(2):aa
192 133:AUE_SETAUDIT:setaudit(2):aa
193 134:AUE_GETUSERAUDIT:getuseraudit(2):no
194 135:AUE_SETUSERAUDIT:setuseraudit(2):no
195 # AUE_AUDITSVC is a placeholder and will not be generated
196 136:AUE_AUDITSVC:auditsvc(2) - place holder:no
197 # AUE_AUDITON is a placeholder and will not be generated
198 138:AUE_AUDITON:auditon(2) - place holder:no
199 139:AUE_AUDITON_GTERMID:auditon(2) - GETTERMID command:no
200 140:AUE_AUDITON_STERMID:auditon(2) - SETTERMID command:no
201 141:AUE_AUDITON_GPOLICY:auditon(2) - get audit policy flags:aa
202 142:AUE_AUDITON_SPOLICY:auditon(2) - set audit policy flags:as
203 143:AUE_AUDITON_GESTATE:auditon(2) - GESTATE command:no
204 144:AUE_AUDITON_SESTATE:auditon(2) - SESTATE command:no
205 145:AUE_AUDITON_GQCTRL:auditon(2) - get queue control parameters:as
206 146:AUE_AUDITON_SQCTRL:auditon(2) - set queue control parameters:as
207 147:AUE_GETKERNSTATE:getkernstate(2):no
208 148:AUE_SETKERNSTATE:setkernstate(2):no
209 149:AUE_GETPORTAUDIT:getportaudit(2):no
210 150:AUE_AUDITSTAT:auditstat(2):no
211 153:AUE_ENTERPROM:enter prom:na
212 154:AUE_EXITPROM:exit prom:na
213 158:AUE_IOCTL:ioctl(2):io
214 173:AUE_ONESIDE:one-sided session record:no
215 174:AUE_MSGGETL:msggetl(2):no
216 175:AUE_MSGRCVL:msgrcvl(2):no
217 176:AUE_MSGSNDL:msgsndl(2):no
218 177:AUE_SEMGETL:semgetl(2):no
219 178:AUE_SHMGETL:shmgetl(2):no
220 183:AUE_SOCKET:socket(2):nt
221 184:AUE_SENDTO:sendto(2):nt
222 # AUE_PIPE is a potentially very high-volume event, use with caution
223 185:AUE_PIPE:pipe(2):no
224 186:AUE_SOCKETPAIR:socketpair(2):no
225 187:AUE_SEND:send(2):no
226 188:AUE_SENDMSG:sendmsg(2):nt
227 189:AUE_RECV:recv(2):no
228 190:AUE_RECVMSG:recvmsg(2):nt
229 191:AUE_RECVFROM:recvfrom(2):nt
230 # AUE_READ is a potentially very high-volume event, use with caution
231 192:AUE_READ:read(2):no
232 193:AUE_GETDENTS:getdents(2):no
233 194:AUE_LSEEK:lseek(2):no
234 # AUE_WRITE is a potentially very high-volume event, use with caution
235 195:AUE_WRITE:write(2):no
236 196:AUE_WRITEV:writev(2):no
237 197:AUE_NFS:nfs server:no
238 198:AUE_READV:readv(2):no
239 199:AUE_OSTAT:old stat(2):no
240 200:AUE_SETUID:setuid(2):pm
241 201:AUE_STIME:old stime(2):as
242 202:AUE_UTIME:old utime(2):no
243 203:AUE_NICE:old nice(2):pm
244 204:AUE_OSETPGRP:old setpgrp(2):no
245 205:AUE_SETGID:old setgid(2):pm
246 206:AUE_READL:readl(2):no
247 207:AUE_READVL:readvl(2):no
248 208:AUE_FSTAT:fstat(2):no
249 209:AUE_DUP2:dup2(2):no
250 # AUE_MMAP is a potentially very high-volume event, use with caution
251 210:AUE_MMAP:mmap(2):no
252 # AUE_AUDIT is a potentially very high-volume event, use with caution
253 211:AUE_AUDIT:audit(2):no
254 212:AUE_PRIOCNTLSYS:priocntlsys(2):pm
255 213:AUE_MUNMAP:munmap(2):cl
256 214:AUE_SETEGID:setegid(2):pm
257 215:AUE_SETEUID:seteuid(2):pm
258 216:AUE_PUTMSG:putmsg(2):nt
259 217:AUE_GETMSG:getmsg(2):nt
260 218:AUE_PUTPMSG:putpmsg(2):nt
261 219:AUE_GETPMSG:getpmsg(2):nt
262 # AUE_AUDITSYS is a placeholder and will not be generated
263 220:AUE_AUDITSYS:audit system calls place holder:no
264 221:AUE_AUDITON_GETKMASK:auditon(2) - get kernel mask:aa
265 222:AUE_AUDITON_SETKMASK:auditon(2) - set kernel mask:as
266 223:AUE_AUDITON_GETCWD:auditon(2) - get current working directory:aa,as
267 224:AUE_AUDITON_GETCAR:auditon(2) - get current active root:aa,as
268 225:AUE_AUDITON_GETSTAT:auditon(2) - get audit statistics:as
269 226:AUE_AUDITON_SETSTAT:auditon(2) - reset audit statistics:as
270 227:AUE_AUDITON_SETUMASK:auditon(2) - set mask per audit uid:as
271 228:AUE_AUDITON_SETSMASK:auditon(2) - set mask per session ID:as
272 229:AUE_AUDITON_GETCOND:auditon(2) - get audit state:aa
273 230:AUE_AUDITON_SETCOND:auditon(2) - set audit state:as
274 231:AUE_AUDITON_GETCLASS:auditon(2) - get event class:aa,as
275 232:AUE_AUDITON_SETCLASS:auditon(2) - set event class:as
276 233:AUE_FUSERS:utssys(2) - fusers:fa
277 234:AUE_STATVFS:statvfs(2):fa
278 235:AUE_XSTAT:xstat(2):no
279 236:AUE_LXSTAT:lxstat(2):no
280 237:AUE_LCHOWN:lchown(2):fm
281 238:AUE_MEMCNTL:memcntl(2):ot
282 239:AUE_SYSINFO:sysinfo(2):as
283 240:AUE_XMKNOD:xmknod(2):no
284 241:AUE_FORK1:fork1(2):ps
285 # AUE_MODCTL is a placeholder and will not be generated
286 242:AUE_MODCTL:modctl(2) system call place holder:no
287 243:AUE_MODLOAD:modctl(2) - load module:as
288 244:AUE_MODUNLOAD:modctl(2) - unload module:as
289 # AUE_MODCONFIG is a place holder and will not be generated
290 245:AUE_MODCONFIG:modctl(2) - no longer generated:no
291 246:AUE_MODADDMAJ:modctl(2) - bind module:as
292 247:AUE_SOCKACCEPT:getmsg-accept:nt
293 248:AUE_SOCKCONNECT:putmsg-connect:nt
294 249:AUE_SOCKSEND:putmsg-send:nt
295 250:AUE_SOCKRECEIVE:getmsg-receive:nt
296 251:AUE_ACLSET:acl(2) - SETACL command:fm
297 252:AUE_FACLSET:facl(2) - SETACL command:fm
298 # AUE_DOORFS is a placeholder and will not be generated
299 253:AUE_DOORFS:doorfs(2) - system call place holder:no
300 254:AUE_DOORFS_DOOR_CALL:doorfs(2) - DOOR_CALL:ip
301 255:AUE_DOORFS_DOOR_RETURN:doorfs(2) - DOOR_RETURN:ip
302 256:AUE_DOORFS_DOOR_CREATE:doorfs(2) - DOOR_CREATE:ip
303 257:AUE_DOORFS_DOOR_REVOKE:doorfs(2) - DOOR_REVOKE:ip
304 258:AUE_DOORFS_DOOR_INFO:doorfs(2) - DOOR_INFO:ip
305 259:AUE_DOORFS_DOOR_CRED:doorfs(2) - DOOR_CRED:ip
306 260:AUE_DOORFS_DOOR_BIND:doorfs(2) - DOOR_BIND:ip
307 261:AUE_DOORFS_DOOR_UNBIND:doorfs(2) - DOOR_UNBIND:ip
308 262:AUE_P_ONLINE:p_online(2):as
309 263:AUE_PROCESSOR_BIND:processor_bind(2):as
310 264:AUE_INST_SYNC:inst_sync(2):as
311 265:AUE_SOCKCONFIG:configure socket:nt
312 266:AUE_SETAUDIT_ADDR:setaudit_addr(2):aa
313 267:AUE_GETAUDIT_ADDR:getaudit_addr(2):aa
314 268:AUE_UMOUNT2:umount2(2):as
315 # AUE_FSAT and all AUE_OPENAT_* codes are obsolete and will not be generated
316 269:AUE_FSAT:fsat(2) - place holder:no
317 270:AUE_OPENAT_R:openat(2) - read:no
318 271:AUE_OPENAT_RC:openat(2) - read,creat:no
319 272:AUE_OPENAT_RT:openat(2) - read,trunc:no
320 273:AUE_OPENAT_RTC:openat(2) - read,creat,trunc:no
321 274:AUE_OPENAT_W:openat(2) - write:no
322 275:AUE_OPENAT_WC:openat(2) - write,creat:no
323 276:AUE_OPENAT_WT:openat(2) - write,trunc:no
324 277:AUE_OPENAT_WTC:openat(2) - write,creat,trunc:no
325 278:AUE_OPENAT_RW:openat(2) - read,write:no
326 279:AUE_OPENAT_RWC:openat(2) - read,write,creat:no
327 280:AUE_OPENAT_RWT:openat(2) - read,write,trunc:no
328 281:AUE_OPENAT_RWTC:openat(2) - read,write,creat,trunc:no
329 282:AUE_RENAMEAT:renameat(2):no
330 283:AUE_FSTATAT:fstatat(2):no
331 284:AUE_FCHOWNAT:fchownat(2):no
332 285:AUE_FUTIMESAT:futimesat(2):no
333 286:AUE_UNLINKAT:unlinkat(2):no
334 287:AUE_CLOCK_SETTIME:clock_settime(3RT):as
335 288:AUE_NTP_ADJTIME:ntp_adjtime(2):as
336 289:AUE_SETPPRIV:setppriv(2):pm
337 290:AUE_MODDEVPLCY:modctl(2) - configure device policy:as
338 291:AUE_MODADDPRIV:modctl(2) - configure additional privilege:as
339 292:AUE_CRYPTOADM:kernel cryptographic framework:as
340 293:AUE_CONFIGKSSL:configure kernel SSL:as
341 294:AUE_BRANDSYS:brandsys(2):ot
342 295:AUE_PF_POLICY_ADDRULE:Add IPsec policy rule:as
343 296:AUE_PF_POLICY_DELRULE:Delete IPsec policy rule:as
344 297:AUE_PF_POLICY_CLONE:Clone IPsec policy:as
345 298:AUE_PF_POLICY_FLIP:Flip IPsec policy:as
346 299:AUE_PF_POLICY_FLUSH:Flush IPsec policy rules:as
347 300:AUE_PF_POLICY_ALGS:Update IPsec algorithms:as
348 # AUE_PORTFS is a placeholder and won't be generated.
349 301:AUE_PORTFS:portfs(2) - file events source - place holder:no
351 305:AUE_PORTFS_ASSOCIATE:portfs(2) - file events source - PORT_ASSOCIATE:fa
352 306:AUE_PORTFS_DISSOCIATE:portfs(2) - file events source - PORT_DISSOCIATE:fa
354 307:AUE_SETSID:setsid(2):pm
355 308:AUE_SETPGID:setpgid(2):pm
356 309:AUE_FACCESSAT:faccessat(2):no
357 310:AUE_AUDITON_GETAMASK:auditon(2) - get default user preselection mask:aa
358 311:AUE_AUDITON_SETAMASK:auditon(2) - set default user preselection mask:as
359 312:AUE_PSECFLAGS:psecflags(2) - set process security flags:pm
361 # user level audit events
362 # 2048 - 6143 Reserved
364 # 6000 - 7999 allocated for Solaris
366 6144:AUE_at_create:at-create atjob:ua
367 6145:AUE_at_delete:at-delete atjob (at or atrm):ua
368 6146:AUE_at_perm:at-permission:no
369 6147:AUE_cron_invoke:cron-invoke:ua
370 6148:AUE_crontab_create:crontab-crontab created:ua
371 6149:AUE_crontab_delete:crontab-crontab deleted:ua
372 6150:AUE_crontab_perm:crontab-persmisson:no
373 6151:AUE_inetd_connect:inetd connect:na
374 6152:AUE_login:login - local:lo
375 6153:AUE_logout:logout:lo
376 6154:AUE_telnet:login - telnet:lo
377 6156:AUE_mountd_mount:mount:na
378 6157:AUE_mountd_umount:unmount:na
380 6160:AUE_halt_solaris:halt(1m):ss
381 6161:AUE_reboot_solaris:reboot(1m):ss
382 6163:AUE_passwd:passwd:lo
383 6165:AUE_ftpd:ftp access:lo
384 6166:AUE_init_solaris:init(1m):ss
385 6167:AUE_uadmin_solaris:uadmin(1m):no
386 6168:AUE_shutdown_solaris:shutdown(1b):ss
387 6169:AUE_poweroff_solaris:poweroff(1m):ss
388 6170:AUE_crontab_mod:crontab-modify:ua
389 6171:AUE_ftpd_logout:ftp logout:lo
390 6172:AUE_ssh:login - ssh:lo
391 6173:AUE_role_login:role login:lo
392 6180:AUE_prof_cmd:profile command:ua,as
393 6181:AUE_filesystem_add:add filesystem:as
394 6182:AUE_filesystem_delete:delete filesystem:as
395 6183:AUE_filesystem_modify:modify filesystem:as
396 6184:AUE_network_add:add network attributes:as
397 6185:AUE_network_delete:delete network attributes:as
398 6186:AUE_network_modify:modify network attributes:as
399 6187:AUE_printer_add:add printer:as
400 6188:AUE_printer_delete:delete printer:as
401 6189:AUE_printer_modify:modify printer:as
402 6190:AUE_scheduledjob_add:add scheduled job:ua
403 6191:AUE_scheduledjob_delete:delete scheduled job:ua
404 6192:AUE_scheduledjob_modify:modify scheduled job:ua
405 6193:AUE_serialport_add:add serial port:as
406 6194:AUE_serialport_delete:delete serial port:as
407 6195:AUE_serialport_modify:modify serial port:as
408 6196:AUE_usermgr_add:add user/user attributes:ua
409 6197:AUE_usermgr_delete:delete user/user attributes:ua
410 6198:AUE_usermgr_modify:modify user/user attributes:ua
411 6199:AUE_uauth:authorization used:ua,as
412 6200:AUE_allocate_succ:allocate-device success:ot
413 6201:AUE_allocate_fail:allocate-device failure:ot
414 6202:AUE_deallocate_succ:deallocate-device success:ot
415 6203:AUE_deallocate_fail:deallocate-device failure:ot
416 6205:AUE_listdevice_succ:allocate-list devices success:ot
417 6206:AUE_listdevice_fail:allocate-list devices failure:ot
418 6207:AUE_create_user:create user:no
419 6208:AUE_modify_user:modify user:no
420 6209:AUE_delete_user:delete user:no
421 6210:AUE_disable_user:disable user:no
422 6211:AUE_enable_user:enable user:no
423 6212:AUE_newgrp_login:newgrp login:lo
424 6213:AUE_admin_authenticate:admin login:lo
425 6214:AUE_kadmind_auth:authenticated kadmind request:ua
426 6215:AUE_kadmind_unauth:unauthenticated kadmind req:ua
427 6216:AUE_krb5kdc_as_req:kdc authentication svc request:ap
428 6217:AUE_krb5kdc_tgs_req:kdc tkt-grant svc request:ap
429 6218:AUE_krb5kdc_tgs_req_2ndtktmm:kdc tgs 2ndtkt mismtch:ap
430 6219:AUE_krb5kdc_tgs_req_alt_tgt:kdc tgs issue alt tgt:ap
431 6220:AUE_smserverd:smserverd:ot
432 6221:AUE_screenlock:screenlock - lock:lo
433 6222:AUE_screenunlock:screenlock - unlock:lo
434 6223:AUE_zone_state:zoneadmd:ss
435 6224:AUE_inetd_copylimit:inetd copylimit:na
436 6225:AUE_inetd_failrate:inetd failrate:na
437 6226:AUE_inetd_ratelimit:inetd ratelimit:na
438 6227:AUE_zlogin:login - zlogin:lo
439 6228:AUE_su_logout:su logout:lo
440 6229:AUE_role_logout:role logout:lo
441 6230:AUE_attach:attach device:ot
442 6231:AUE_detach:detach device:ot
443 6232:AUE_remove:remove/eject device:ot
444 6233:AUE_pool_import:import device into pool:ot
445 6234:AUE_pool_export:export device from pool:ot
446 6235:AUE_dladm_create_secobj:create network security object:as,cy
447 6236:AUE_dladm_delete_secobj:delete network security object:as,cy
448 6237:AUE_uadmin_shutdown:uadmin(1m) - shutdown:ss
449 6238:AUE_uadmin_reboot:uadmin(1m) - reboot:ss
450 6239:AUE_uadmin_dump:uadmin(1m) - dump:ss
451 6240:AUE_uadmin_freeze:uadmin(1m) - freeze:ss
452 6241:AUE_uadmin_remount:uadmin(1m) - remount:ss
453 6242:AUE_uadmin_ftrace:uadmin(1m) - ftrace:ss
454 6243:AUE_uadmin_swapctl:uadmin(1m) - swapctl:ss
455 6244:AUE_smbd_session:smbd(1m) session setup:lo
456 6245:AUE_smbd_logoff:smbd(1m) session logoff:lo
457 6246:AUE_vscan_quarantine:vscand(1m) quarantine infected file:na
458 6247:AUE_ndmp_connect:ndmp connect:na
459 6248:AUE_ndmp_disconnect:ndmp disconnect:na
460 6249:AUE_ndmp_backup:ndmp backup:na
461 6250:AUE_ndmp_restore:ndmp restore:na
462 6251:AUE_cpu_ondemand:set ondemand CPU freq governor:ss
463 6252:AUE_cpu_performance:set max CPU freq governor:ss
464 6253:AUE_cpu_threshold:set CPU freq threshold:ss
465 6254:AUE_uadmin_thaw:uadmin(1m) - thaw after freeze:ss,na
466 6255:AUE_uadmin_config:uadmin(1m) - config:ss
469 # SMF(5) svc.configd events (svcadm(1M) related)
471 6260:AUE_smf_enable:persistently enable service instance:ss
472 6261:AUE_smf_tmp_enable:temporarily enable service instance:ss
473 6262:AUE_smf_disable:persistently disable service instance:ss
474 6263:AUE_smf_tmp_disable:temporarily disable service instance:ss
475 6264:AUE_smf_restart:restart service instance:ss
476 6265:AUE_smf_refresh:refresh service instance:ss
477 6266:AUE_smf_clear:clear service instance state:ss
478 6267:AUE_smf_degrade:set service instance degraded state:ss
479 6268:AUE_smf_immediate_degrade:immediately set service instance degraded state:ss
480 6269:AUE_smf_maintenance:set service instance persistent maintenance state:ss
481 6270:AUE_smf_immediate_maintenance:immediately set service instance persistent maintenance state:ss
482 6271:AUE_smf_immtmp_maintenance:immediately set service instance temporary maintenance state:ss
483 6272:AUE_smf_tmp_maintenance:set service instance maintenance temporary state:ss
484 6273:AUE_smf_milestone:set service management facility milestone:ss
486 # SMF(5) svc.configd miscellaneous events
488 6275:AUE_smf_read_prop:read restricted access property value:as
490 # SMF(5) svc.configd events (svccfg(1M) related)
492 6280:AUE_smf_create:create service instance object:as
493 6281:AUE_smf_delete:delete service instance object:as
494 6282:AUE_smf_create_pg:create persistent service property group:as
495 6283:AUE_smf_create_npg:create non-persistent service property group:as
496 6284:AUE_smf_delete_pg:delete persistent service property group:as
497 6285:AUE_smf_delete_npg:delete non-persistent service property group:as
498 6286:AUE_smf_create_snap:create repository snapshot:as
499 6287:AUE_smf_delete_snap:delete repository snapshot:as
500 6288:AUE_smf_attach_snap:attach repository snapshot:as
501 6289:AUE_smf_annotation:annotate transaction:as,ss
502 6290:AUE_smf_create_prop:create service instance property:as
503 6291:AUE_smf_change_prop:change service instance property:as
504 6292:AUE_smf_delete_prop:delete service instance property:as
508 6300:AUE_nwam_enable:enable nwam profile object:ss
509 6301:AUE_nwam_disable:disable nwam profile object:ss
513 6310:AUE_ilb_create_healthcheck:create ILB health check:as
514 6311:AUE_ilb_delete_healthcheck:delete ILB health check:as
515 6312:AUE_ilb_create_rule:create ILB rule:as
516 6313:AUE_ilb_delete_rule:delete ILB rule:as
517 6314:AUE_ilb_disable_rule:disable ILB rule:as
518 6315:AUE_ilb_enable_rule:enable ILB rule:as
519 6316:AUE_ilb_add_server:add ILB server:as
520 6317:AUE_ilb_disable_server:disable ILB server:as
521 6318:AUE_ilb_enable_server:enable ILB server:as
522 6319:AUE_ilb_remove_server:remove ILB server:as
523 6320:AUE_ilb_create_servergroup:create ILB server group:as
524 6321:AUE_ilb_delete_servergroup:delete ILB server group:as
528 6330:AUE_netcfg_update:create or modify configuration object:ss
529 6331:AUE_netcfg_remove:remove configuration object from repository:ss
533 6400:AUE_tpm_takeownership:take ownership of TPM:as
534 6401:AUE_tpm_clearowner:clear ownership of TPM:as
535 6402:AUE_tpm_setoperatorauth:set TPM operator authorization:as
536 6403:AUE_tpm_setownerinstall:set TPM ownership flag:as
537 6404:AUE_tpm_selftestfull:test all TPM protected capabilities:as
538 6405:AUE_tpm_certifyselftest:perform full TPM self-test:as
539 6406:AUE_tpm_continueselftest:complete TPM self-test:as
540 6407:AUE_tpm_ownersetdisable:change the status of TPM disable flag:as
541 6408:AUE_tpm_ownerclear:perform the clear operation under TPM owner auth:as
542 6409:AUE_tpm_disableownerclear:disable TPM_OwnerClear command permanently:as
543 6410:AUE_tpm_forceclear:perform TPM clear operation under physical access:as
544 6411:AUE_tpm_disableforceclear:disable ForceClear execution until next startup:as
545 6412:AUE_tpm_physicaldisable:disable TPM physical presence:as
546 6413:AUE_tpm_physicalenable:enable TPM physical presence:as
547 6414:AUE_tpm_physicaldeactivate:set TPM deactivated flag:as
548 6415:AUE_tpm_settempdeactivated:set volatile TPM deactivated flag to TRUE:as
549 6416:AUE_tpm_settempdeactivated2:set volatile TPM deactivated flag TRUE with auth:as
550 6417:AUE_tpm_physicalpresence:set the TPM physical presence flag:as
551 6418:AUE_tpm_fieldupgrade:update TPM protected capabilities:as
552 6419:AUE_tpm_resetlockvalue:reset TPM failed authorization attempt lock:as
554 # hotplugd(1m) events
556 6500:AUE_hotplug_state:change hotplug connection state:ss
557 6501:AUE_hotplug_set:set hotplug bus private options:ss
562 6650:AUE_sudo:sudo(1m):lo,ua,as