I started eXpert-BSM on a Solaris 2.6 or 2.7 system and the system immediately crashed. Why?
It is clearly stated in the documentation and in the output from the installation script that Solaris 2.6 and 2.7 have a bug that causes this crash, and therefore must have patches installed. See the System Requirements section in the user documentation. Q: eXpert-BSM keeps producing alerts about one type of operation which we consider perfectly legitimate according to our site’s security policy. How can we make it stop alerting about this condition while still monitoring everything else? A: First, make sure that all parameters are properly configured. If so, you can choose to disable selected heuristics by removing them from the list of enabled heuristics in resource-object/config/eXpert-Config.inc.