 |
 |  |
 |
 | NOTE: This procedure will make the saved event log your current
system log. Any new events will be logged to the end of the current
log file not the previously active log file that was renamed to
a temporary filename. You may want to save your active log before
following these steps. After you are finished viewing the saved
log, copy the active log file back to sysevent.evt. |
 |
 |  |
 |
To
display an archived log file that was saved in log file format to
a shared drive on the server:
From the HP-UX command line (logged in as root):
cd /var/opt/asu/lanman/logs
then:
cp sysevent.evt temporary_filename
Copy your archived event log from the shared directory
where it resides to:
/var opt/asu/lanman/logs
and name it sysevent.evt.
You can then view it in the event viewer.
Event Logging is operational for most successful audit events.
See the Advanced Server/9000 Concepts and Planning Guide
for information on managing the audit policy. In some cases, failure
events are not logged.