audit logs stored in /var/audit
audit - utility to control the auditing system
Use praudit to output log in human readable form
Use praudit /dev/auditpipe to access the logs in real time
Use auditreduce to filter records from the file