From mboxrd@z Thu Jan 1 00:00:00 1970 From: Matthew Booth Subject: Format of audit logs Date: Tue, 08 May 2007 19:02:06 +0100 Message-ID: <1178647326.4728.2.camel@localhost.localdomain> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1464773623==" Return-path: Received: from [192.168.1.8] (sebastian-int.corp.redhat.com [172.16.52.221]) by pobox.surrey.redhat.com (8.12.11.20060308/8.12.11) with ESMTP id l48I27C1032028 for ; Tue, 8 May 2007 19:02:07 +0100 List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit List-Id: linux-audit@redhat.com --===============1464773623== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-aOBJKfeWKtkOAUjiS2Jh" --=-aOBJKfeWKtkOAUjiS2Jh Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Can anybody point me to a document which describes the format of logs generated by auditd in RHEL 4. This is for a customer, and is for human consumption. I don't need to parse them. I know they're reasonably self-explanatory, but it would be a significant amount of work to document it myself. Thanks, Matt --=20 Matthew Booth, RHCA, RHCSS Red Hat, Global Professional Services M: +44 (0)7977 267231 GPG ID: D33C3490 GPG FPR: 3733 612D 2D05 5458 8A8A 1600 3441 EA19 D33C 3490 --=-aOBJKfeWKtkOAUjiS2Jh Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iD8DBQBGQLseNEHqGdM8NJARAidEAJ9GVt0KOVpe1il4RZhfZnM0/ytMrQCfetUU 13AjvBZHZpEdRs38Ug6tRQ8= =exf7 -----END PGP SIGNATURE----- --=-aOBJKfeWKtkOAUjiS2Jh-- --===============1464773623== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1464773623==--