aboutsummaryrefslogtreecommitdiffstats
path: root/framework/src/audit/docs/autrace.8
diff options
context:
space:
mode:
authorAshlee Young <ashlee@wildernessvoice.com>2016-01-20 01:10:01 +0000
committerAshlee Young <ashlee@wildernessvoice.com>2016-01-20 01:10:11 +0000
commit19d701ddf07d855128ded0cf2b573ce468e3bdd6 (patch)
tree0edcd3461ca903c76e431bb7c6348c42a0f12488 /framework/src/audit/docs/autrace.8
parentfac6fbefbfad1cf837ddd88bc0d330559c8eb6f9 (diff)
Removing Suricata and Audit from source repo, and updated build.sh to avoid building suricata. Will re-address this in C release via tar balls.
Change-Id: I3710076f8b7f3313cb3cb5260c4eb0a6834d4f6e Signed-off-by: Ashlee Young <ashlee@wildernessvoice.com>
Diffstat (limited to 'framework/src/audit/docs/autrace.8')
-rw-r--r--framework/src/audit/docs/autrace.838
1 files changed, 0 insertions, 38 deletions
diff --git a/framework/src/audit/docs/autrace.8 b/framework/src/audit/docs/autrace.8
deleted file mode 100644
index 36a62248..00000000
--- a/framework/src/audit/docs/autrace.8
+++ /dev/null
@@ -1,38 +0,0 @@
-.TH AUTRACE: "8" "Jan 2007" "Red Hat" "System Administration Utilities"
-.SH NAME
-autrace \- a program similar to strace
-.SH SYNOPSIS
-.B autrace
-.I program
-.RB [ \-r ]
-.RI [ program-args ]...
-.SH DESCRIPTION
-\fBautrace\fP is a program that will add the audit rules to trace a process similar to strace. It will then execute the \fIprogram\fP passing \fIarguments\fP to it. The resulting audit information will be in the audit logs if the audit daemon is running or syslog. This command deletes all audit rules prior to executing the target program and after executing it. As a safety precaution, it will not run unless all rules are deleted with
-.B auditctl
-prior to use.
-.SH OPTIONS
-.TP
-.B \-r
-Limit syscalls collected to ones needed for analyzing resource usage. This could help people doing threat modeling. This saves space in logs.
-.SH "EXAMPLES"
-The following illustrates a typical session:
-
-.nf
-.B autrace /bin/ls /tmp
-.B ausearch \-\-start recent \-p 2442 \-i
-.fi
-
-and for resource usage mode:
-
-.nf
-.B autrace \-r /bin/ls
-.B ausearch \-\-start recent \-p 2450 \-\-raw | aureport \-\-file \-\-summary
-.B ausearch \-\-start recent \-p 2450 \-\-raw | aureport \-\-host \-\-summary
-.fi
-
-.SH "SEE ALSO"
-.BR ausearch (8),
-.BR auditctl (8).
-
-.SH AUTHOR
-Steve Grubb