public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Need help, we are receiving type=SYSCALL with auid=unset event entries
@ 2014-06-03 20:28 Briane Lin
  2014-06-04  1:56 ` Steve Grubb
       [not found] ` <5CB21FE316752445AF212D47C8BE561127541357@XMBVAG75.northgrum.com>
  0 siblings, 2 replies; 3+ messages in thread
From: Briane Lin @ 2014-06-03 20:28 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 480 bytes --]

We are receiving LINUX RHEL versions 5 and 6 in our environment with 
type=SYSCALL and auid=unset event types.

We are unable to properly monitor an event with AUID=unset, does anyone 
know why we are currently seeing these and what is the resolution?

Thanks!

Briane Lin
IBM Global Technology Services - Americas
Identity and Access Management, Automation Solutions
(Email): brlin@us.ibm.com
(Office): (720) 395-2049

"The only easy day was yesterday." 
     - US Navy Seals -


[-- Attachment #1.2: Type: text/html, Size: 911 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Need help, we are receiving type=SYSCALL with auid=unset event entries
  2014-06-03 20:28 Need help, we are receiving type=SYSCALL with auid=unset event entries Briane Lin
@ 2014-06-04  1:56 ` Steve Grubb
       [not found] ` <5CB21FE316752445AF212D47C8BE561127541357@XMBVAG75.northgrum.com>
  1 sibling, 0 replies; 3+ messages in thread
From: Steve Grubb @ 2014-06-04  1:56 UTC (permalink / raw)
  To: linux-audit

On Tuesday, June 03, 2014 01:28:40 PM Briane Lin wrote:
> We are unable to properly monitor an event with AUID=unset, does anyone 
> know why we are currently seeing these and what is the resolution?

If you have an unset auid and its supposed to be meaningful, then the way that 
people are logging in does not set the auid. This can be done in entrypoint 
software by calling audit_setloginuid(). Pam has coding examples.

-Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

* RE: EXT :Need help, we are receiving type=SYSCALL with auid=unset event entries
       [not found] ` <5CB21FE316752445AF212D47C8BE561127541357@XMBVAG75.northgrum.com>
@ 2014-06-04 19:28   ` Briane Lin
  0 siblings, 0 replies; 3+ messages in thread
From: Briane Lin @ 2014-06-04 19:28 UTC (permalink / raw)
  To: Boyce, Kevin P (AS); +Cc: linux-audit


[-- Attachment #1.1.1: Type: text/plain, Size: 1530 bytes --]

Thanks Kevin.

The systems are at RHEL server release 6.5 (Santiago)

audit.conf and audit.rules shown below from two systems.


 
 


 



 
 


 



Briane Lin
IBM Global Technology Services - Americas
Identity and Access Management, Automation Solutions
(Email): brlin@us.ibm.com
(Office): (720) 395-2049

"The only easy day was yesterday." 
     - US Navy Seals -





From:   "Boyce, Kevin P (AS)" <Kevin.Boyce@ngc.com>
To:     Briane Lin/Phoenix/IBM@IBMUS
Date:   06/04/2014 07:00 AM
Subject:        RE: EXT :Need help, we are receiving type=SYSCALL with 
auid=unset event entries



You might get some better help if you can be a bit more specific.
What version of auditd, kernel, etc. are you running?
What do the contents of your audit.rules and auditd.conf files look like?
 
 
 
From: linux-audit-bounces@redhat.com [
mailto:linux-audit-bounces@redhat.com] On Behalf Of Briane Lin
Sent: Tuesday, June 03, 2014 4:29 PM
To: linux-audit@redhat.com
Subject: EXT :Need help, we are receiving type=SYSCALL with auid=unset 
event entries
 
We are receiving LINUX RHEL versions 5 and 6 in our environment with 
type=SYSCALL and auid=unset event types. 

We are unable to properly monitor an event with AUID=unset, does anyone 
know why we are currently seeing these and what is the resolution? 

Thanks! 

Briane Lin 
IBM Global Technology Services - Americas 
Identity and Access Management, Automation Solutions
(Email): brlin@us.ibm.com 
(Office): (720) 395-2049 

"The only easy day was yesterday." 
    - US Navy Seals - 

[-- Attachment #1.1.2: Type: text/html, Size: 5858 bytes --]

[-- Attachment #1.2: Type: image/jpeg, Size: 40899 bytes --]

[-- Attachment #1.3: Type: image/jpeg, Size: 46271 bytes --]

[-- Attachment #1.4: Type: image/jpeg, Size: 44700 bytes --]

[-- Attachment #1.5: Type: image/jpeg, Size: 37978 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-06-04 19:28 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-06-03 20:28 Need help, we are receiving type=SYSCALL with auid=unset event entries Briane Lin
2014-06-04  1:56 ` Steve Grubb
     [not found] ` <5CB21FE316752445AF212D47C8BE561127541357@XMBVAG75.northgrum.com>
2014-06-04 19:28   ` EXT :Need " Briane Lin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox