From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: (no subject) Date: Wed, 3 May 2006 13:31:24 -0400 Message-ID: <200605031331.24933.sgrubb@redhat.com> References: <954E3479CC27224785179CA04904214D018B71AE@0668-its-exmp01.us.saic.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <954E3479CC27224785179CA04904214D018B71AE@0668-its-exmp01.us.saic.com> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com Cc: "Kirkwood, David A" List-Id: linux-audit@redhat.com On Wednesday 03 May 2006 13:21, Kirkwood, David A wrote: > I don't see any timestamps on audit events. How can I bracket events > between to dates /times? The ausearch utility was created to view the audit records. It extracts that information from the event. Can you give that a try? ausearch -ts 1:00:00 -i (This also assumes you have the audit daemon running.) -Steve