From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric Paris Subject: Re: Repository of audit events Date: Wed, 09 Apr 2014 12:32:34 -0400 Message-ID: <1397061154.23819.20.camel@flatline.rdu.redhat.com> References: <1397024726.23793.121.camel@swtf.swtf.dyndns.org> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1397024726.23793.121.camel@swtf.swtf.dyndns.org> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: burn@swtf.dyndns.org Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com To the best of my knowledge there is no way to generate every record type. I did send sgrubb the beginnings of me trying to write a suite of programs to exercise some of them for hopeful eventual inclusion in the auparse checker tool... I really think such a thing would be useful... On Wed, 2014-04-09 at 16:25 +1000, Burn Alting wrote: > All, > > Does there exist a repository of audit events that could be used to test > changes to the audit parsing code? > > Although turning on > > -a always,exit -F arch=b32 -S all > and > -a always,exit -F arch=b64 -S all > > for a while does tend to generate a lot of audit, but it's clearly not > exhaustive so I am hoping we have some repositories that are shareable > and one can test against. > > Rgds > > -- > Linux-audit mailing list > Linux-audit@redhat.com > https://www.redhat.com/mailman/listinfo/linux-audit