All of lore.kernel.org
 help / color / mirror / Atom feed
* Question regarding ntpd
@ 2016-09-27 22:05 Sullivan, Daniel [CRI]
  2016-09-27 23:16 ` Steve Grubb
  0 siblings, 1 reply; 13+ messages in thread
From: Sullivan, Daniel [CRI] @ 2016-09-27 22:05 UTC (permalink / raw)
  To: linux-audit@redhat.com; +Cc: Jarsulic, Michael [CRI]

Hi,

I have what I hope to be a quick question regarding auditing ntpd.  I am looking at my auditd log file and I see this same entry being repeated every second:

type=SYSCALL msg=audit(1475012493.972:5325): arch=c000003e syscall=159 success=yes exit=0 a0=7ffd7498eb00 a1=861 a2=0 a3=1 items=0 ppid=1 pid=5357 auid=4294967295 uid=38 gid=38 euid=38 suid=38 fsuid=38 egid=38 sgid=38 fsgid=38 tty=(none) ses=4294967295 comm="ntpd" exe="/usr/sbin/ntpd" key="time-change"
type=SYSCALL msg=audit(1475012494.971:5326): arch=c000003e syscall=159 success=yes exit=0 a0=7ffd7498eb00 a1=861 a2=0 a3=1 items=0 ppid=1 pid=5357 auid=4294967295 uid=38 gid=38 euid=38 suid=38 fsuid=38 egid=38 sgid=38 fsgid=38 tty=(none) ses=4294967295 comm="ntpd" exe="/usr/sbin/ntpd" key="time-change"
type=SYSCALL msg=audit(1475012495.972:5327): arch=c000003e syscall=159 success=yes exit=0 a0=7ffd7498eb00 a1=861 a2=0 a3=1 items=0 ppid=1 pid=5357 auid=4294967295 uid=38 gid=38 euid=38 suid=38 fsuid=38 egid=38 sgid=38 fsgid=38 tty=(none) ses=4294967295 comm="ntpd" exe="/usr/sbin/ntpd" key="time-change”

This is generating large amounts of log data.  I am not an expert in auditd log analysis.  Is this expected behavior?  I am unsure of what the key time-change value of this log data is, and am wondering if this indicates some sort of misconfiguration or problem with ntpd.  From looking at the output of tcpdump it does not look like I am polling every second, so I am wondering why this activity is occurring.   If anybody could advise on how to decipher these log entries I would appreciate it.  Thank you for your help and advisement.

Best,

Dan Sullivan




********************************************************************************
This e-mail is intended only for the use of the individual or entity to which
it is addressed and may contain information that is privileged and confidential.
If the reader of this e-mail message is not the intended recipient, you are 
hereby notified that any dissemination, distribution or copying of this
communication is prohibited. If you have received this e-mail in error, please 
notify the sender and destroy all copies of the transmittal. 

Thank you
University of Chicago Medicine and Biological Sciences 
********************************************************************************

--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2016-10-13 12:25 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-09-27 22:05 Question regarding ntpd Sullivan, Daniel [CRI]
2016-09-27 23:16 ` Steve Grubb
2016-09-28  0:06   ` John Jasen
2016-09-28  1:21     ` Sullivan, Daniel [CRI]
2016-09-28  0:21   ` Ryan Sawhill
2016-09-28  1:45     ` Sullivan, Daniel [CRI]
2016-09-28  1:17   ` Sullivan, Daniel [CRI]
2016-10-10 21:48   ` L. A. Walsh
2016-10-11 16:07     ` Steve Grubb
2016-10-11 20:49       ` Paul Moore
2016-10-11 21:37         ` L. A. Walsh
2016-10-13 12:25           ` Paul Moore
2016-10-11 16:33     ` Ryan Sawhill

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.