This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. How-To Make Linux System Auditing a Little Easier Auditing your system and network covers an important aspect of security, detection. It is your last line of defense. It is crucial that you have in place a means of determining the state of your system and to detect unauthorized logins and system changes. To accomplish this there are several programs and utilities that are made available but using them all on a daily basis and over a period of time can be an over whelming task if you don't design a good strategy. The design must be simple enough, yet effective, so that... Copyright SANS Institut