> >> The Solaris audit facility will record a command execution as soon as> Yes, that''s a special case of my reason #3 - (sufficient) auditing may > not be enabled.I''d like to let this run. I''d like to see if it makes sense to audit in addition to build the history. The down side being an additional required privilege. Thankx, Gary..
Gary Winiger wrote:>>>> The Solaris audit facility will record a command execution as soon as > >> Yes, that''s a special case of my reason #3 - (sufficient) auditing may >> not be enabled. > > I''d like to let this run. I''d like to see if it makes sense > to audit in addition to build the history. The down side being > an additional required privilege.but zpool operations require all privilege today anyway IIRC. -- Darren J Moffat
On Wed, May 10, 2006 at 08:15:15AM -0700, Gary Winiger wrote:> > >> The Solaris audit facility will record a command execution as soon as > > > Yes, that''s a special case of my reason #3 - (sufficient) auditing may > > not be enabled. > > I''d like to let this run. I''d like to see if it makes sense > to audit in addition to build the history. The down side being > an additional required privilege.Couldn''t the auditing be done kernel-side? But, yes, good point on the privilege requirement if done in user-land.