public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* auid = unset
@ 2019-05-03 19:31 Joshua Ammons
  2019-05-03 19:43 ` Steve Grubb
  0 siblings, 1 reply; 8+ messages in thread
From: Joshua Ammons @ 2019-05-03 19:31 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 489 bytes --]

Hello, I just wanted to see if anyone has had much success with configuring redhat systems to reduce and/or eliminate the occurrence of auid = unset in the audit events?  I found the following redhat article that provides a fix by updating a grub setting for auditd but this doesn't seem to have much of an effect, as I still see large number of unset values in the logs.

https://access.redhat.com/solutions/971883

Thank you in advance for any information you may have on this.



[-- Attachment #1.2: Type: text/html, Size: 2449 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 8+ messages in thread
* auid unset
@ 2007-12-06 18:01 Kirkwood, David A.
  2007-12-06 19:07 ` klausk
  0 siblings, 1 reply; 8+ messages in thread
From: Kirkwood, David A. @ 2007-12-06 18:01 UTC (permalink / raw)
  To: linux-audit

Hi,

 

I need some help with configuration. First, I do not remember how to
tell the version of the auditd I am running. I tried to get it by
pulling strings with no success. The larger problem is I am configuring
a RHEL4U5 system. I have a RHEL4U4 system that runs correctly and
supplies the AUID when specified with aureport. The RHEL4U5 system has
this parameter as "unset" rather than the AUID or uid or anything else
to identify who was attempting to run failed commands. 

If someone can help me with what needs to be set, I would appreciate it.
I compared all of the obvious files, such as all pam files, the
audit.rules, auditd.conf and syslog.conf and they all seem to be the
same.

Both systems run Linux 2.6.9-42.ELsmp.
 

Thanks in advance. 

 

David A. Kirkwood

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2019-05-03 19:43 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-05-03 19:31 auid = unset Joshua Ammons
2019-05-03 19:43 ` Steve Grubb
  -- strict thread matches above, loose matches on Subject: below --
2007-12-06 18:01 auid unset Kirkwood, David A.
2007-12-06 19:07 ` klausk
2007-12-06 19:18   ` klausk
2007-12-06 19:42   ` Kirkwood, David A.
2007-12-06 22:25     ` Steve Grubb
2007-12-07 14:30       ` Kirkwood, David A.

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox