"auditd is the userspace component to
the Linux Auditing System. It's
responsible for writing audit records to
the disk. Viewing the logs is done with
the
ausearch
or
aureport
utilities."
Slide 14
Watching file access
Monitoring system calls
Recording commands run by a user
Recording security events
Monitoring network access