
73
Setting Up Event Notification
dhcp-101.up.wirex.com has had 10 security events since Tue
Oct 12 11:10:00 2004
•
Summary Notification:
The Summary notification displays SubDo-
main security events that are logged and lists the number of individ-
ual occurrences, including the date of the last occurrence. For
example:
SubDomain:
PERMITTING
access
to
capability
'setgid'
(httpd2-prefork(6347)
profile
/usr/sbin/httpd2-prefork
active /usr/sbin/httpd2-prefork) 2 times, the latest at
Sat Oct
9 16:05:54 2004.
•
Verbose Notification:
The Verbose notification displays unmodified,
logged SubDomain security events. It tells you every time an event
occurs and writes a new line in the Verbose log. These security
events include the date and time the event occurred, when the appli-
cation profile permits access as well as rejects access, and the type
of file permission access that is permitted or rejected. Verbose Notifi-
cat
i
on
al
so
r
epor
t
s
sever
al
messages
t
hat
t
he
l
ogpr
of
t
ool
(
see
“
Log-
prof
”
on
page61)
uses
t
o
i
nt
er
pr
et
pr
of
i
l
es.
For
exampl
e:
• Oct 9 15:40:31 SubDomain: PERMITTING r access to
/etc/apache2/httpd.conf (httpd2-prefork(6068) profile
/usr/sbin/httpd2-prefork active /usr/sbin/httpd2-pre-
fork)
Note:
To
enabl
e
Secur
i
t
y
Event
Not
i
f
i
cat
i
on,
r
ef
er
t
o
“
Managing Nov-
ell AppArmor and Security Event Status
”
on
page43.
The
Enabl
e
Security Event Notification screen displays as follows: