linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* audit triggers sent email
@ 2017-04-12 13:14 Maria Tsiolakki
  2017-04-12 16:53 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Maria Tsiolakki @ 2017-04-12 13:14 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 296 bytes --]

Hello,

I have setup the audit log service (on red hat linux 7.3) and I have 
placed rules such as when a user access a specif directory to  log the 
action in the audit log.I want to go a further step, and get an email 
notification when this happens.
Can this be set up?

Thank you

Maria

**


[-- Attachment #1.2: Type: text/html, Size: 22481 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: audit triggers sent email
  2017-04-12 13:14 audit triggers sent email Maria Tsiolakki
@ 2017-04-12 16:53 ` Steve Grubb
  0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2017-04-12 16:53 UTC (permalink / raw)
  To: linux-audit; +Cc: Maria Tsiolakki

Hello,

On Wednesday, April 12, 2017 9:14:27 AM EDT Maria Tsiolakki wrote:
> I have setup the audit log service (on red hat linux 7.3) and I have
> placed rules such as when a user access a specific directory to log the
> action in the audit log. I want to go a further step, and get an email
> notification when this happens. Can this be set up?

Sort of. You would have to create an audispd plugin to do it. I think that 
this is a nice question to make a blog post out of. So, I started a series of 
blogs today to show people how to write special purpose plugins.

In essence you would put a key on the event you want to get an email on, write 
a plugin that filters for that key, then call sendmail to create the message. 
If you have patience, I will give you the source code in the blog[1] to do 
this over the next couple days. If you are in a hurry and can write your own 
plugin, then skeleton code is here:

https://github.com/linux-audit/audit-userspace/tree/master/contrib/plugin

-Steve

[1] - http://security-plus-data-science.blogspot.com/

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-04-12 16:53 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-04-12 13:14 audit triggers sent email Maria Tsiolakki
2017-04-12 16:53 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).