public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: Linux Audit <linux-audit@redhat.com>
Subject: audit 2.7.2 released
Date: Mon, 13 Feb 2017 10:32:18 -0500	[thread overview]
Message-ID: <1996093.VO5rSWzXSG@x2> (raw)

Hello,

I've just released a new version of the audit daemon. It can be downloaded 
from http://people.redhat.com/sgrubb/audit. It will also be in rawhide
soon. The ChangeLog is:

- Rename whole auparse classifier subsystem to normalizer
- Add documentation about networking and systemd
- Adjust text in auparse normalizer
- In ausearch, fix parsing of kernel anomaly events
- Add filesystem object to the auparse normalizer
- Add basic support for formatted output in ausearch
- Add 'extra' options for csv output in ausearch
- Add event kind metadata to the auparse normalizer
- Add event kind metadata to the ausearch csv format
- Add auparse normalizer support to some anomaly events
- In libaudit logging functions, fill in hostname if we have real tty
- Add new virtualization events
- Fix compile time feature detection in auditctl

In the 2.7.x releases is a big new feature that I have not talked very much 
about. Starting with this release I'll start talking about it. The audit logs 
can now be normalized. This means we can do lots of new things around 
analytics. So much so, that I will send a separate email discussing this new 
feature. I'll also start posting to a blog to explain all the things that you 
can now do. If you have the ability to compile the sources, do it and try 

ausearch --start today --format text

Besides this, the release fixes a bug in parsing of kernel anaomaly events for 
ausearch/report and we added types for some new virtualization events.

I will try to get a 2.7.3 release out in a little under 2 weeks. This is to 
get one last release off of the svn site before it goes away. Testing and 
feedback around the normalizer would be greatly appreciated. As mentioned, 
I'll start another thread to discuss it.

Please let me know if you run across any problems with this release.

-Steve

                 reply	other threads:[~2017-02-13 15:32 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1996093.VO5rSWzXSG@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox