From: LC Bruzenak <lenny@magitekltd.com>
To: "Miloslav Trmač" <mitr@redhat.com>
Cc: linux-audit <linux-audit@redhat.com>
Subject: Re: Announcing audit-viewer
Date: Tue, 27 May 2008 10:20:41 -0500 [thread overview]
Message-ID: <1211901641.6568.29.camel@homeserver> (raw)
In-Reply-To: <1210932706.2822.45.camel@amilo>
Mirek,
First thing I want to say is that this is a really good first release
tool! There are a lot of things I like and so far not a lot I don't.
I have a couple of questions though:
1: The filters all seem to work fine, and I like the ability to store
the filter config. One thing I believe would be helpful, though, it to
have a way of temporarily filtering from the main screen without having
to add a specific filter, save it and then later remove it.
Like a "filter on": button added near the "Edit". It would need a
corresponding "clear" to reset. I recall my own use of the handy
Evolution mail search tool.
2: I'd also like to be able to launch results in a new window. The
reason for this is I see how helpful it would be to see, as an example,
a side-by-side audit comparison between hosts. What I'd do is filter on
a particular hostname & open that in a new window. Then I'd filter on a
different hostname and open those results in a new window. Then I could
easily compare what 2 different machines audit results look like. This
would be in a situation where I am seeing some audit anomaly or some key
in the audit data on one host but not another.
I'd consider these to be non-critical enhancements because I can do
everything I say above in (1) by making more filter configs and loading
those. I can also do the request in (2) by launching multiple
audit-viewers and then manipulating as desired.
But so far in my testing these are the things I see which would be
helpful and I thought you would appreciate some feedback. Again, kudos
on a nice initial release!
LCB.
--
LC (Lenny) Bruzenak
lenny@magitekltd.com
prev parent reply other threads:[~2008-05-27 15:20 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-05-16 10:11 Announcing audit-viewer Miloslav Trmač
2008-05-22 22:27 ` LC Bruzenak
2008-06-02 15:01 ` Miloslav Trmač
2008-06-02 17:47 ` LC Bruzenak
2008-05-27 15:20 ` LC Bruzenak [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1211901641.6568.29.camel@homeserver \
--to=lenny@magitekltd.com \
--cc=linux-audit@redhat.com \
--cc=mitr@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.