All of lore.kernel.org
 help / color / mirror / Atom feed
* processing audit data
@ 2007-12-09 16:41 Thorsten Scherf
  2007-12-09 17:30 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Thorsten Scherf @ 2007-12-09 16:41 UTC (permalink / raw)
  To: linux-audit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

HI folks,

wo we have any plans to ship auditd with some kind of data processing
tool in the future? maybe as audispd plugin? just having a single log
file with a bunch of data isn't really helpful, although we have tools
like ausearch or aureport. customers often ask for something more
visually. :)

Thanks,
Thorsten

- --
Life is complicated, sendmail.cf reflects this!


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFHXBq0wfkoLTuSgLsRAtUFAJsFg1Sga8AYFmqEOy70CcCcp5kknACglTY3
mIgugCnhnnrYWzR+0fFyW9g=
=rFNq
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: processing audit data
  2007-12-09 16:41 processing audit data Thorsten Scherf
@ 2007-12-09 17:30 ` Steve Grubb
  0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2007-12-09 17:30 UTC (permalink / raw)
  To: linux-audit

On Sunday 09 December 2007 11:41:24 Thorsten Scherf wrote:
> Do we have any plans to ship auditd with some kind of data processing
> tool in the future? 

That depends and what you mean.

> maybe as audispd plugin?

That would be for realtime usage...we plan to do a few for analysis and 
protocol conversion/support.

> just having a single log  file with a bunch of data isn't really helpful,
> although we have tools like ausearch or aureport. customers often ask for
> something more visually. :)

Well, that is different from realtime. And yes we plan a GUI based reporting 
tool. But with the auparse library, it should be easy for anyone to write 
some apps.

-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2007-12-09 17:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-12-09 16:41 processing audit data Thorsten Scherf
2007-12-09 17:30 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.