109.3. AIX Auditing (im_aixaudit)
This module parses events in the AIX Audit format. This module reads directly from the kernel. See also xm_aixaudit.
109.3.1. Configuration
The im_aixaudit module accepts the following directives in addition to the common module directives.
- DeviceFile
-
This optional directive specifies the device file from which to read audit events. If this is not specified, it defaults to
/dev/audit
.
109.3.2. Fields
See the xm_aixaudit Fields.