![]() |
![]() |
| ||||||||||||||||||||||||
acl TokenThe acl token records information about Access Control Lists. This token consists of four fixed fields:
The praudit command displays the acl token as follows:
The following figure shows the format of the acl token. Figure 23-4 acl Token Format ![]() arbitrary TokenThe arbitrary token encapsulates data for the audit trail. This token consists of four fixed fields and an array of data. The fixed fields are as follows:
The remainder of the token is composed of one or more items of the specified type. The praudit command displays the arbitrary token as follows:
The following figure shows the format of the arbitrary token. Figure 23-5 arbitrary Token Format ![]() The following table shows the possible values of the print format field. Table 23-5. Table 23-5 Values for the arbitrary Token's Print Format Field
The following table shows the possible values of the item size field. Table 23-6 Values for the arbitrary Token's Item Size Field
arg TokenThe arg token contains information about the arguments to a system call: the argument number of the system call, the argument value, and an optional description. This token allows a 32-bit integer system-call argument in an audit record. The arg token has five fields:
The praudit command displays the arg token as follows:
The following figure shows the format of the arg token. Figure 23-6 arg Token Format ![]() attr TokenThe attr token contains information from the file vnode. This token has seven fields:
See the statvfs(2) man page for further information about the file system ID and the device ID. The attr token usually accompanies a path token. The attr token is produced during path searches. In the event of a path-search error, there is no vnode available to obtain the necessary file information. Therefore, the attr token is not included as part of the audit record. The praudit command displays the attr token as follows:
The following figure shows the format of an attr token. Figure 23-7 attr Token Format
| ||||||||||||||||||||||||
| ||||||||||||||||||||||||