From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id B0CF5C4167B for ; Wed, 20 Oct 2021 17:06:05 +0000 (UTC) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [216.205.24.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 19C75613A3 for ; Wed, 20 Oct 2021 17:06:05 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 19C75613A3 Authentication-Results: mail.kernel.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1634749564; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=qme91zyagC+ggTHEY4Lz7fAZG1pFlpxYjcefWI3r6dg=; b=hUkM04abTHpje/oQ/MNht65whZQnq4vAAxTGf6ktYyKGVXGUDicpJIbOEEA5853Xp1EFQb ZhPwXZ7kQVMUCgRheHbHdYMxVDL/DRll9y7xKNdmDEH394iVx3pgJ4dgsHDMCTCg+Tm6py Nb0FgeqMe69JjKBB+G+kI3lUYpYS9U8= Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-363-yTVtCQBAMEuYYBnGY_GDpg-1; Wed, 20 Oct 2021 13:06:00 -0400 X-MC-Unique: yTVtCQBAMEuYYBnGY_GDpg-1 Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.12]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id E2CD110060F2; Wed, 20 Oct 2021 17:05:56 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.21]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 7AB8660CA1; Wed, 20 Oct 2021 17:05:56 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 77F584E58F; Wed, 20 Oct 2021 17:05:55 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id 19KH5rbw022803 for ; Wed, 20 Oct 2021 13:05:53 -0400 Received: by smtp.corp.redhat.com (Postfix) id C23E360936; Wed, 20 Oct 2021 17:05:53 +0000 (UTC) Received: from x2.localnet (unknown [10.22.8.70]) by smtp.corp.redhat.com (Postfix) with ESMTP id 56AD31B5C2; Wed, 20 Oct 2021 17:05:21 +0000 (UTC) From: Steve Grubb To: linux-audit@redhat.com Subject: Re: why no LOGOUT event record on some OSes Date: Wed, 20 Oct 2021 13:05:20 -0400 Message-ID: <3135484.aeNJFYEL58@x2> Organization: Red Hat In-Reply-To: <38b20678-b4f6-91c4-8743-775e7546641f@163.com> References: <38b20678-b4f6-91c4-8743-775e7546641f@163.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-loop: linux-audit@redhat.com Cc: Li Zhijian , Li Zhijian X-BeenThere: linux-audit@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Linux Audit Discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.12 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=linux-audit-bounces@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Hello, On Wednesday, October 20, 2021 10:55:02 AM EDT Li Zhijian wrote: > I'm new to audit, then i observed that there is no LOGOUT event record > in audit.log on my ubuntu 18.04 and debian 8 OSes, while the centos7.4 and > fedora33 have it. > > I google it but get no answer, so am I missing something about the audit > rules or special audit configuration ? The logout events are hardwired into programs. IOW, they do not come from any audit rules. You'd want to see which program the users login with. It is responsible for sending the logout event. You might check the source code of it or simply grep AUDIT_LOGOUT in the source. If it is in the code, then you'd want to see what's happening in the code when a user logs out. -Steve > Below are part of records of audit in my several OSes. > > debian 8 > lizhijian@lkp-bingo:~$ sudo aureport -e -i --summary | grep -i USER > [sudo] password for lizhijian: > 6 USER_START > 6 USER_END > 4 USER_ACCT > 4 USER_CMD > 2 USER_AUTH > 2 USER_LOGIN > > ubuntu 18.04 > lizj@FNSTPC:~$ sudo aureport -e -i --summary | grep USER > 43241 USER_END > 16946 USER_START > 16718 USER_ACCT > 658 USER_AUTH > 543 USER_CMD > 255 USER_LOGIN > 9 USER_ROLE_CHANGE > 5 USER_ERR > 2 USER_CHAUTHTOK > 1 ADD_USER > > fedora 33 > [root@iaas-rpma linux]# aureport -e -i --summary | grep USER > 7356 CRYPTO_KEY_USER > 2103 USER_START > 1649 USER_END > 1268 USER_ACCT > 1108 USER_ROLE_CHANGE > 1029 USER_AUTH > 895 USER_LOGIN > 789 USER_LOGOUT > 60 USER_CMD > 14 USER_ERR > 3 USER_MGMT > 3 USER_CHAUTHTOK > 1 ADD_USER > > Thanks > > -- > Linux-audit mailing list > Linux-audit@redhat.com > https://listman.redhat.com/mailman/listinfo/linux-audit -- Linux-audit mailing list Linux-audit@redhat.com https://listman.redhat.com/mailman/listinfo/linux-audit