public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* creating and inserting audits
@ 2010-09-07 20:38 Nestler, Roger - IS
  2010-09-07 21:00 ` Steve Grubb
  2010-09-07 21:02 ` LC Bruzenak
  0 siblings, 2 replies; 8+ messages in thread
From: Nestler, Roger - IS @ 2010-09-07 20:38 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 1101 bytes --]


Using syslog it seems straight forward to insert a new message ,  'syslog (LOG_NOTICE, "Hello This is just a notice")' for instance.

Does this capability exist already in linux audit and I'm just not seeing it???

Is it a bad idea to build and then to insert a custom audit/message, or any standard audit, into the audit.log file?

If so are there any problems to look out for , e.g event id/sequence number collisions, auparse or ausearch problems, formatting issues to adhere to???

Thanks



________________________________
This e-mail and any files transmitted with it may be proprietary and are intended solely for the use of the individual or entity to whom they are addressed. If you have received this e-mail in error please notify the sender.
Please note that any views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of ITT Corporation. The recipient should check this e-mail and any attachments for the presence of viruses. ITT accepts no liability for any damage caused by any virus transmitted by this e-mail.

[-- Attachment #1.2: Type: text/html, Size: 3235 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2010-09-08 20:34 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-09-07 20:38 creating and inserting audits Nestler, Roger - IS
2010-09-07 21:00 ` Steve Grubb
2010-09-07 21:02 ` LC Bruzenak
2010-09-07 21:17   ` Steve Grubb
2010-09-08 13:48     ` Nestler, Roger - IS
2010-09-08 14:25       ` Steve Grubb
2010-09-08 14:56         ` Nestler, Roger - IS
2010-09-08 20:34           ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox