Less known Solaris features: BART
Apropos auditing. There is a small but cool tool in Solaris. It solves the problem of “No, i haven´t changed anything on the system”. It´s called BART, the Basic Audit Reporting Tool. It a really simple tool and it´s really easy to use.
Okay, let´s assume after some days of work you finally configured all components of your new system. Okay, create a nice place to store the output of the bart tool. After this you start bart for the first time to create the first manifest of your system.
The manifest stores all informations about the files. This is the example for the
Now lets change some files:
Okay, enough changes. Let´s create a new manifest of the changed
/etc. Pipe it to a different file.
Now we can compare the baseline manifest with the actual manifest.
This command prints all differences between the two manifests and thus the difference between the tow states of the system
As i wrote before: A really nice tool.
Want to learn more?
For more information about this tool visit Using the Basic Audit Reporting Tool.