Steve,
The aureport utility has an option to use an alternative input file.
Because I have to move my logs, I really need an alternative input
directory, preferably a starting point, since my saved logs are:
/var/log/audit-archive/<YEAR>/<MONTH>/<DAY> .
Then I could do "aureport --topdir /var/log/audit-archive/2009/12 "
and get all the 12/2009 events up to now.
What do you think?
I thought about creating a different flat directory and just linking
the files I want, however I do not think the current options will
allow this either. I guess that would be the easiest change though, to
allow the -if parameter to be a directory or a file.
Thx,
LCB.
--
LC (Lenny) Bruzenak