From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Monitoring events Date: Thu, 8 Jun 2006 10:04:16 -0400 Message-ID: <200606081004.16261.sgrubb@redhat.com> References: <44882C43.70704@ornl.gov> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <44882C43.70704@ornl.gov> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Thursday 08 June 2006 09:55, Steve wrote: > Ideally, I would like to only capture (or parse) events pertaining to > rules I have created (since other system processes are using auditd as > well). =A0Is there's any kind of identifier that ties events to rules? Which kernel are you using? Are your events only watches or do you care a= bout=20 syscall auditing as well (meaning you have set some syscall audit rules) = ? -Steve