Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* auditd rule error
@ 2018-06-11 12:39 Joshua Ammons
  2018-06-11 14:27 ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Joshua Ammons @ 2018-06-11 12:39 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 407 bytes --]

On a server running RHEL 7.2 the audit rules fail to load due to an error on this rule:

-a always,exit -F arch=b64 -S setuid -F a0=0 -F exe=/usr/bin/su -F key=10.2.5.b-elevated-privs-session

>From what I have found it seems "exe" may not be a valid field on this specific O.S. - is this correct?  Does anyone have any recommendations on how to track elevated privileges for all RHEL 6/7 systems?



[-- Attachment #1.2: Type: text/html, Size: 2321 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-06-11 14:49 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-06-11 12:39 auditd rule error Joshua Ammons
2018-06-11 14:27 ` Steve Grubb
2018-06-11 14:49   ` Joshua Ammons

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox