linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* audit rules watching paths
@ 2017-03-12  4:48 Warron French
  2017-03-12 23:21 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Warron French @ 2017-03-12  4:48 UTC (permalink / raw)
  To: linux-audit

I know that I can add to the audit.rules file a rule like

-w /etc/ -p rawx -k watch_Etc

But how far down will this sort of audit rule monitor /etc/?  How many 
levels deep?


Thanks.

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: audit rules watching paths
  2017-03-12  4:48 audit rules watching paths Warron French
@ 2017-03-12 23:21 ` Steve Grubb
  0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2017-03-12 23:21 UTC (permalink / raw)
  To: linux-audit

On Saturday, March 11, 2017 11:48:53 PM EDT Warron French wrote:
> I know that I can add to the audit.rules file a rule like
> 
> -w /etc/ -p rawx -k watch_Etc
> 
> But how far down will this sort of audit rule monitor /etc/?  How many
> levels deep?

The "-w /etc" is the same thing as "-F dir=/etc". They both go down all the 
way until you hit a new mount point. So, for the sake of discussion, suppose 
/dev/sdb3 was mounted at /etc/sysconfig/, then anything under /etc/sysconfig/ 
will not be audited. To fix this, you need to add a rule with the -q option to 
tell the kernel that the mounted file system should be considered equivalent to 
the directory being watched.

I also think that if you have any symlinks that point out of the subtree, that 
they may not get watched because they actually resolve to another path. I'd 
have to test that to be 100% sure, though.

Also note that during path resolution if there is a permission problem at a 
directory level and the object was below it, you may not get an event or only 
an event at the directory where the permission was blocked.

-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-03-12 23:21 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-03-12  4:48 audit rules watching paths Warron French
2017-03-12 23:21 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).