sat_interpret(1M)

sat_interpret - convert audit records from binary to English

As shipped in IRIX 6.5. First release of IRIX 6.5.

NAME
     sat_interpret - convert audit records from binary to English

SYNOPSIS
     sat_interpret [ -bdfln ] [ file ]

DESCRIPTION
     sat_interpret takes binary audit records from standard input or
     optionally a file and prints the records to standard output in English.

     To illustrate the output format of sat_interpret, here is a sample output
     record:

          Event type       = sat_open_ro
          Outcome          = Success
          Sequence number  = 1
          Time of event    = Mon Dec 09 18:06:27.43 PST 1991
          System call      = open
          Error status     = 0 (No error)
          Process ID       = 55 (chkconfig)
          Parent process   = 54
          Curr working dir = /
          Process label    = dblow (msenlow/minthigh)
          SAT ID           = root
          User id          = root
          Group id         = sys
          Terminal dev.    = 127, 255
          File descriptor  = 3
          Open flags       = O_RDONLY
          Created          = No
          Pathname information:
            Device/Inode   = (22, 32)/920
            Owner          = root
            Group          = sys
            Mode bits      = 0100644 (-rw-r--r--)
            Label          = dblow (msenlow/minthigh)
            Requested name = "/etc/config/verbose"
            Actual name    = "/etc//config//verbose"

     Here is an example of the same event displayed in brief mode:

          Mon Dec  9 18:06:27.43 PST 1991
          +sat_open_ro (open), Success
          Process 55 (chkconfig), ppid 54, tty NODEV, cwd /
          SAT ID root, uid root, gid sys, label dblow
          file descriptor 3, O_RDONLY, not created
          Pathname information:
            920   -rw-r--r--  root   sys    /etc/config/verbose [dblow]
            Actual name: /etc//config//verbose

     Here is an example of the same event displayed in linear mode, although
     your line wrapping may differ from what is shown here:
          sat_open_ro (open) + (ok) pid:55 chkconfig sreuid:root,root,r
          oot regid:sys,sys,sys label:dblow fd:3,(O_RDONLY),exists path
          :920,-rw-r--r--,root,sys,dblow,"/etc/config/verbose","/etc//c
          onfig//verbose"


OPTIONS
     -b   ``Brief'' mode.  Display the record header and pathname output in a
          space-saving format.  This mode is terse, but it is much easier to
          view multiple records on a screen.

          If the event was successful, the event name is preceded by a `+'
          character.  If the event failed, it is preceded by a `-'.  This
          makes it easy to scan for successes or failures.  The rest of the
          fields are self-explanatory, as they say.

     -d   Debug mode.  Prints out generally uninteresting information about
          the file offset of the record, record and header size, and so on.

     -f   File descriptors are mapped to the filenames to which they apply
          whenever possible.

     -l   Linear mode.  Display the record in a very terse, one line per
          record format.

     -n   Normalize process IDs.  The first process ID encountered is mapped
          to one, the second to two, and so on.  Inode numbers are not
          printed, a "-" is printed instead.  This option is handy for audit
          trail comparisons.

     -z timezone
          Override the timezone recorded in the audit file.  No error checking
          is done on the timezone specified.  See timezone(4) for allowable
          syntax of the timezone.

EXAMPLE
     sat_interpret is ordinarily used in combination with other audit filters.
     To filter all records generated by guest and display them, execute this
     sequence:

          sat_reduce -u guest sat_xxxxxx | sat_interpret | more


NOTES
     Information about user names and group names is stored in the record
     header while label names are retrieved from the local workstation.  This
     means the user and group names reported are those from the machine where
     the records were generated, while the label names are from the machine
     sat_interpret was run on.

SEE ALSO
     audit(1M), sat_reduce(1M), sat_select(1M), sat_summarize(1M), satd(1M).

     IRIX Admin: Backup, Security, and Accounting