Audit Logging

The messages generated by the firewall and other services are written to the file /var/log/System.log under Mac OS X. Make sure to review these logs on a regular basis to look for evidence of attacks or compromise. A monitoring tool, such as swatch, can help by automating the monitoring.

If you want to use swatch as described in Chapter 4, you must start it with the following command:

swatch -tail-file=/var/log/System.log --config-file=swatch.config

This will tell swatch the path to the System.log file, so it knows where to find the logs on Mac OS X. See Section 4.1.6 for more information on this tool.

Get 802.11 Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.