From mboxrd@z Thu Jan 1 00:00:00 1970 From: James Antill Subject: Re: Resolving syscall numbers Date: Mon, 12 Jun 2006 11:56:52 -0400 Message-ID: <1150127812.29837.0.camel@code.and.org> References: <448D83E2.3010907@ornl.gov> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1697954575==" Return-path: Received: from mail.and.org (vpn83-130.boston.redhat.com [172.16.83.130]) by pobox.corp.redhat.com (8.12.8/8.12.8) with ESMTP id k5CFus6I023903 for ; Mon, 12 Jun 2006 11:56:54 -0400 In-Reply-To: <448D83E2.3010907@ornl.gov> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============1697954575== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-jGu4HC5Ir60UICHB+Rcn" --=-jGu4HC5Ir60UICHB+Rcn Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Mon, 2006-06-12 at 11:10 -0400, Steve wrote: > This may not be appropriate for this list, if it isn't I apologize and=20 > you may ignore it. >=20 > Is there an quick way to resolve the syscall number that auditd returns=20 > within a message to a syscall name? (ie. 5->open)? >=20 > I am programming in C, if that helps. Use audit_syscall_to_name(num, audit_detect_machine()) --=20 James Antill Red Hat --=-jGu4HC5Ir60UICHB+Rcn Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iD8DBQBEjY7E11eXTEMrxtQRAhsFAJ42o3slK4a6x8oaSK+0mUpeiadMMQCfQhvb oDF13cgPCG6RCSB9z4Qruf4= =OD8u -----END PGP SIGNATURE----- --=-jGu4HC5Ir60UICHB+Rcn-- --===============1697954575== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1697954575==--