auditctl — configure system audit parameters
Contents
Description
The auditctl() system call directs the kernel to open a new audit trail log file. It requires an
appropriate privilege. The auditctl() system call opens new files, but auditon(2) is used to disable the
audit log.
Errors
The auditctl() system call will fail if:
[EINVAL] The path is invalid.
[EPERM] The process does not have sufficient permission to complete the operation.
History
The OpenBSM implementation was created by McAfee Research, the security division of McAfee Inc., under
contract to Apple Computer Inc. in 2004. It was subsequently adopted by the TrustedBSD Project as the
foundation for the OpenBSM distribution.
Name
auditctl — configure system audit parameters
Return Values
Upon successful completion, the value 0 is returned; otherwise the value -1 is returned and the global
variable errno is set to indicate the error.
See Also
auditon(2), libbsm(3), auditd(8)
Synopsis
#include<bsm/audit.h>intauditctl(constchar*path);
