public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* capturing audit data with ausearch -i
@ 2013-12-10 22:17 Levy, Mark (ESS)
  2013-12-11  2:23 ` Aaron Lewis
  2013-12-11 12:58 ` Steve Grubb
  0 siblings, 2 replies; 3+ messages in thread
From: Levy, Mark (ESS) @ 2013-12-10 22:17 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 364 bytes --]

Hi,

Were trying to find a way to capture the linux audit data and then pass it thru to ausearch -I  and then send the data to our SEIM product for ingestion.
Does the audispd allow  the ausearch -I to be used as an arg?
What would be the best way to attempt this?
We would be collecting from hundreds of linux servers.

Thanks for your input.


Mark


[-- Attachment #1.2: Type: text/html, Size: 950 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2013-12-11 12:58 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-12-10 22:17 capturing audit data with ausearch -i Levy, Mark (ESS)
2013-12-11  2:23 ` Aaron Lewis
2013-12-11 12:58 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox