public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Repository of audit events
@ 2014-04-09  6:25 Burn Alting
  2014-04-09 16:32 ` Eric Paris
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Burn Alting @ 2014-04-09  6:25 UTC (permalink / raw)
  To: linux-audit

All,

Does there exist a repository of audit events that could be used to test
changes to the audit parsing code?

Although turning on 

-a always,exit -F arch=b32 -S all
and
-a always,exit -F arch=b64 -S all

for a while does tend to generate a lot of audit, but it's clearly not
exhaustive so I am hoping we have some repositories that are shareable
and one can test against.

Rgds

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2014-04-11 15:27 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-04-09  6:25 Repository of audit events Burn Alting
2014-04-09 16:32 ` Eric Paris
2014-04-09 16:33 ` lists_todd
2014-04-09 17:19 ` Steve Grubb
2014-04-10  0:16   ` Burn Alting
2014-04-10  1:26   ` Peter Moody
2014-04-11  3:36     ` Mimi Zohar
2014-04-11 14:07       ` Steve Grubb
2014-04-11 15:26         ` Mimi Zohar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox