All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: Wouter van Verre <woutervanverre@outlook.com>
Cc: "linux-audit@redhat.com" <linux-audit@redhat.com>
Subject: Re: Remote logging with autitd
Date: Thu, 13 Nov 2014 21:44:53 -0500	[thread overview]
Message-ID: <9904045.iPF9lTPz31@x2> (raw)
In-Reply-To: <DUB131-W886F03E34A0C33F40E6FABDD8F0@phx.gbl>

On Thursday, November 13, 2014 11:23:59 PM Wouter van Verre wrote:
> However, in my plugin I only  seems to receive data from the central (i.e.
> local) server... 

The feed to audispd, right now, is before receiving remote events. Meaning 
that audispd only sees local events and never aggregate events...as things are 
now.

> I draw this conclusion both because I see only one node name, and also
> because I generate TTY events on the client server only (and they show in
> /var/log/audit/audit.log as expected), and these do not show in the output
> from my plugin. Is this the expected behaviour?

Today, yes.

> Are plugins only supposed to receive the locally generated audit events? If
> it is, is there a way to forward the remotely generated data to a plugin on
> the central server?

Yes, and it would take some changes to the listening code to insert the events 
at the right point in the event loop.

-Steve

  reply	other threads:[~2014-11-14  2:44 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-11-01 21:49 Remote logging with autitd Wouter van Verre
2014-11-02 18:12 ` Steve Grubb
2014-11-02 21:16   ` Wouter van Verre
2014-11-02 21:25     ` LC Bruzenak
2014-11-02 22:09       ` Wouter van Verre
2014-11-13 22:23     ` Wouter van Verre
2014-11-14  2:44       ` Steve Grubb [this message]
2014-11-14 15:16         ` AUID question David Flatley
2014-11-14 15:26           ` Steve Grubb
2014-11-18 12:21         ` Remote logging with autitd Wouter van Verre

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9904045.iPF9lTPz31@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=woutervanverre@outlook.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.