All of lore.kernel.org
 help / color / mirror / Atom feed
* Set audisp plugin filters
@ 2017-04-12  8:28 Eytan Naim
  2017-04-12 15:54 ` Richard Guy Briggs
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Eytan Naim @ 2017-04-12  8:28 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1.1: Type: text/plain, Size: 936 bytes --]

Hi,

I am currently developing an audisp plugin that should be as effective as possible.
Therefore, I want to set my own set of filtering rules (2-3 syscalls) and I don't want to get any other audit events from the audisp itself, - I assumed it is possible to set my own plugin rules but I couldn't find it in the audit documentation (Linux Audit API) nor any other audisp plugins examples. Is it even possible?
If not, is it possible to run an auditd of my own in parallel with the original auditd? I assume each auditd can define its own set of audit rules. - Am I right?

Thanks in advance,

[https://signature.imperva.com/assets/imperva-logo.png]
Eytan Naim | SW Engineer
eytan.naim@imperva.com<mailto:eytan.naim@imperva.com> | m: +972 50-225-8833
imperva.com<https://imperva.com> | facebook<https://www.facebook.com/imperva> | linkedin<https://www.linkedin.com/company/imperva> | twitter<https://twitter.com/imperva>


[-- Attachment #1.1.2: Type: text/html, Size: 4718 bytes --]

[-- Attachment #1.2: image001.png --]
[-- Type: image/png, Size: 1488 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-04-12 16:45 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-04-12  8:28 Set audisp plugin filters Eytan Naim
2017-04-12 15:54 ` Richard Guy Briggs
2017-04-12 15:56 ` Paul Moore
2017-04-12 16:45 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.