{
    "mode": "man",
    "parameter": "auvirt",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/auvirt/8/json",
    "generated": "2026-10-07T11:48:08Z",
    "synopsis": "auvirt [ OPTIONS ]",
    "sections": {
        "NAME": {
            "content": "auvirt - a program that shows data related to virtual machines\n\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "auvirt [ OPTIONS ]\n\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "auvirt  shows a list of guest sessions found in the audit logs. If a guest is specified, only\nthe events related to that guest is considered. To specify a guest, both UUID or VM name  can\nbe given.\n\nFor  each  guest session the tool prints a record with the domain name, the user that started\nthe guest, the time when the guest was started and the time when the guest was stopped.\n\nIf the option \"--all-events\" is given a more detailed output is shown.  In  this  mode  other\nrecords  are shown for guest's stops, resource assignments, AVC and anomaly events. The first\nfield indicates the event type and can have the following values: start, stop, res, avc,  and\nanom.\n\nResource  assignments have the additional fields: resource type, reason and resource. And AVC\nrecords have the following additional fields: operation, result, command and target.\n\nBy default, auvirt reads records from the system audit log file. But --stdin and  --file  op‐\ntions can be specified to change this behavior.\n\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "",
            "subsections": [
                {
                    "name": "--all-events",
                    "content": "Show records for all virtualization related events.\n",
                    "long": "--all-events"
                },
                {
                    "name": "--debug",
                    "content": "Print debug messages to stderr.\n",
                    "long": "--debug"
                },
                {
                    "name": "-f --file _",
                    "content": "Read records from the given file instead from the system audit log file.\n",
                    "flag": "-f",
                    "long": "--file"
                },
                {
                    "name": "-h --help",
                    "content": "Print help message and exit.\n",
                    "flag": "-h",
                    "long": "--help"
                },
                {
                    "name": "--proof",
                    "content": "Add  after  each event a line containing all the identifiers of the audit records used\nto calculate the event. Each identifier consists of unix time, milliseconds and serial\nnumber.\n",
                    "long": "--proof"
                },
                {
                    "name": "--show-uuid",
                    "content": "Add the guest's UUID to each record.\n",
                    "long": "--show-uuid"
                },
                {
                    "name": "--stdin",
                    "content": "Read records from the standard input instead from the system audit log file.  This op‐\ntion cannot be specified with --file. The audit events must be in the raw format.\n",
                    "long": "--stdin"
                },
                {
                    "name": "--summary",
                    "content": "Print a summary with information about the events found. The summary contains the con‐\nsidered range of time, the number of guest starts and stops, the  number  of  resource\nassignments,  the  number  of  AVC and anomaly events, and the number of failed opera‐\ntions.\n",
                    "long": "--summary"
                },
                {
                    "name": "-te --end",
                    "content": "Search for events with time stamps equal to or before the given end time.  The  format\nof  end  time depends on your locale. If the date is omitted, today is assumed. If the\ntime is omitted, now is assumed. Use 24 hour clock time rather than AM or PM to  spec‐\nify  time.   An  example date using the enUS.utf8 locale is 09/03/2009. An example of\ntime is 18:00:00. The date format accepted is influenced by the LCTIME  environmental\nvariable.\n\nYou  may  also  use  the  word:  now,  recent,  today, yesterday, this-week, week-ago,\nthis-month, this-year. Today means starting now. Recent is 10 minutes  ago.  Yesterday\nis  1 second after midnight the previous day.  This-week means starting 1 second after\nmidnight on day 0 of the week determined by your locale  (see  localtime).  This-month\nmeans  1 second after midnight on day 1 of the month. This-year means the 1 second af‐\nter midnight on the first day of the first month.\n",
                    "long": "--end"
                },
                {
                    "name": "-ts --start",
                    "content": "Search for events with time stamps equal to or after the given end time. The format of\nend time depends on your locale. If the date is omitted, today is assumed. If the time\nis omitted, midnight is assumed. Use 24 hour clock time rather than AM or PM to  spec‐\nify  time.  An  example  date using the enUS.utf8 locale is 09/03/2009. An example of\ntime is 18:00:00. The date format accepted is influenced by the LCTIME  environmental\nvariable.\n\nYou  may  also  use  the  word:  now, recent, today, yesterday, this-week, this-month,\nthis-year.  Today means starting at 1 second after midnight. Recent is 10 minutes ago.\nYesterday is 1 second after midnight the previous day.   This-week  means  starting  1\nsecond  after midnight on day 0 of the week determined by your locale (see localtime).\nThis-month means 1 second after midnight on day 1 of the month. This-year means the  1\nsecond after midnight on the first day of the first month.\n",
                    "long": "--start"
                },
                {
                    "name": "-u --uuid  _",
                    "content": "Only show events related to the guest with the given UUID.\n",
                    "flag": "-u",
                    "long": "--uuid"
                },
                {
                    "name": "-v --vm  _",
                    "content": "Only show events related to the guest with the given name.\n\n",
                    "flag": "-v",
                    "long": "--vm"
                }
            ]
        },
        "EXAMPLES": {
            "content": "To see all the records in this month for a guest\n",
            "subsections": [
                {
                    "name": "auvirt --start this-month --vm GuestVmName --all-events",
                    "content": ""
                }
            ]
        },
        "SEE ALSO": {
            "content": "aulast(8), ausearch(8), aureport(8).\n\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "Marcelo Cerri\n\nIBM Corp                                      Dec 2011                                     AUVIRT(8)",
            "subsections": []
        }
    },
    "summary": "auvirt - a program that shows data related to virtual machines",
    "flags": [
        {
            "flag": "",
            "long": "--all-events",
            "arg": null,
            "description": "Show records for all virtualization related events."
        },
        {
            "flag": "",
            "long": "--debug",
            "arg": null,
            "description": "Print debug messages to stderr."
        },
        {
            "flag": "-f",
            "long": "--file",
            "arg": null,
            "description": "Read records from the given file instead from the system audit log file."
        },
        {
            "flag": "-h",
            "long": "--help",
            "arg": null,
            "description": "Print help message and exit."
        },
        {
            "flag": "",
            "long": "--proof",
            "arg": null,
            "description": "Add after each event a line containing all the identifiers of the audit records used to calculate the event. Each identifier consists of unix time, milliseconds and serial number."
        },
        {
            "flag": "",
            "long": "--show-uuid",
            "arg": null,
            "description": "Add the guest's UUID to each record."
        },
        {
            "flag": "",
            "long": "--stdin",
            "arg": null,
            "description": "Read records from the standard input instead from the system audit log file. This op‐ tion cannot be specified with --file. The audit events must be in the raw format."
        },
        {
            "flag": "",
            "long": "--summary",
            "arg": null,
            "description": "Print a summary with information about the events found. The summary contains the con‐ sidered range of time, the number of guest starts and stops, the number of resource assignments, the number of AVC and anomaly events, and the number of failed opera‐ tions."
        },
        {
            "flag": "",
            "long": "--end",
            "arg": null,
            "description": "Search for events with time stamps equal to or before the given end time. The format of end time depends on your locale. If the date is omitted, today is assumed. If the time is omitted, now is assumed. Use 24 hour clock time rather than AM or PM to spec‐ ify time. An example date using the enUS.utf8 locale is 09/03/2009. An example of time is 18:00:00. The date format accepted is influenced by the LCTIME environmental variable. You may also use the word: now, recent, today, yesterday, this-week, week-ago, this-month, this-year. Today means starting now. Recent is 10 minutes ago. Yesterday is 1 second after midnight the previous day. This-week means starting 1 second after midnight on day 0 of the week determined by your locale (see localtime). This-month means 1 second after midnight on day 1 of the month. This-year means the 1 second af‐ ter midnight on the first day of the first month."
        },
        {
            "flag": "",
            "long": "--start",
            "arg": null,
            "description": "Search for events with time stamps equal to or after the given end time. The format of end time depends on your locale. If the date is omitted, today is assumed. If the time is omitted, midnight is assumed. Use 24 hour clock time rather than AM or PM to spec‐ ify time. An example date using the enUS.utf8 locale is 09/03/2009. An example of time is 18:00:00. The date format accepted is influenced by the LCTIME environmental variable. You may also use the word: now, recent, today, yesterday, this-week, this-month, this-year. Today means starting at 1 second after midnight. Recent is 10 minutes ago. Yesterday is 1 second after midnight the previous day. This-week means starting 1 second after midnight on day 0 of the week determined by your locale (see localtime). This-month means 1 second after midnight on day 1 of the month. This-year means the 1 second after midnight on the first day of the first month."
        },
        {
            "flag": "-u",
            "long": "--uuid",
            "arg": null,
            "description": "Only show events related to the guest with the given UUID."
        },
        {
            "flag": "-v",
            "long": "--vm",
            "arg": null,
            "description": "Only show events related to the guest with the given name."
        }
    ],
    "examples": [
        "To see all the records in this month for a guest"
    ],
    "see_also": [
        {
            "name": "aulast",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/aulast/8/json"
        },
        {
            "name": "ausearch",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/ausearch/8/json"
        },
        {
            "name": "aureport",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/aureport/8/json"
        }
    ]
}