Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Monitoring events
@ 2006-06-08 13:55 Steve
  2006-06-08 14:04 ` Steve Grubb
  0 siblings, 1 reply; 6+ messages in thread
From: Steve @ 2006-06-08 13:55 UTC (permalink / raw)
  To: linux-audit

I have the program adding rules to Audit now.  Thank you for your help.

I also have my program monitoring the output from auditd (via the 
dispatch option in auditd.conf).

Ideally, I would like to only capture (or parse) events pertaining to 
rules I have created (since other system processes are using auditd as 
well).  Is there's any kind of identifier that ties events to rules?

Thank you again,
Steve

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-06-08 15:23 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-08 13:55 Monitoring events Steve
2006-06-08 14:04 ` Steve Grubb
2006-06-08 14:22   ` Steve
2006-06-08 14:39     ` Steve Grubb
2006-06-08 14:57       ` Steve
2006-06-08 15:23         ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox