audit(7) — Special Files
NAME
audit − audit log interface
DESCRIPTION
This is a special character device that provides an interface for the audit daemon process, /usr/sbin/auditd, to the kernel audit buffers.
RESTRICTIONS
This device should be readable only by root, to protect access by nonsystem processes. The major number assigned to this device must correlate with the corresponding major number designation in the system kernel.
FILES
/dev/audit
RELATED INFORMATION
Security