public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Audit-1.0.14
@ 2006-10-11 11:49 Boyce, Kevin P. (Melbourne, FL)
  2006-10-11 12:24 ` Audit-1.0.14 Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Boyce, Kevin P. (Melbourne, FL) @ 2006-10-11 11:49 UTC (permalink / raw)
  To: Linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 992 bytes --]

I am trying to use a vanilla kernel from kernel.org version 2.6.12 and
2.6.16 with the audit daemon version 1.0.14.  I am using ubuntu, so I
have used alien to convert the redhat binary packages for an x86_64
architecture into *.deb files.  I can install the deb files and the
audit daemon runs, but it has trouble parsing the audit.rules file.  The
error I am getting is "Error sending insert watch request (Invalid
Argument)."

Please help.  I have a requirement to use these two kernel versions, and
unfortunately can't use redhat, fedora, or their kernel binaries.  I
have recompiled my kernel with auditing turned on.  I can look in the
audit.log file and see events being written there when I start and stop
the daemon, so I know the daemon works.  I just need to know how to
parse the log file correctly.  Also when you bypass the log file and
just use auditctl -w <file to watch>, the same error is returned.

Thanks in advance.

Kevin Boyce
kevin.boyce@ngc.com


[-- Attachment #1.2: Type: text/html, Size: 1557 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 5+ messages in thread
* Re: Audit-1.0.14
@ 2006-11-09 19:56 Todd, Charles
  2006-11-13 14:19 ` Audit-1.0.14 Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Todd, Charles @ 2006-11-09 19:56 UTC (permalink / raw)
  To: linux-audit

> On Wednesday 11 October 2006 07:49, Boyce, Kevin P. (Melbourne, FL) wrote:
> > I can install the deb files and the audit daemon runs, but it has trouble
> > parsing the audit.rules file.  The error I am getting is "Error sending
> > insert watch request (Invalid Argument)."

> This is not a parsing error...its worse. The audit 1.0.x series was developed 
> to compliment the RHEL4 kernel. At the time, it was envisioned that the 
> technique used for watches would be accepted upstream. It was rejected due to 
> some overlap with inotify, so the watch system was re-written. The audit 
> 1.2.x series has the code for the new system. Watches were not accepted 
> upstream until the 2.6.18 kernel.

> > I have a requirement to use these two kernel versions, and unfortunately
> > can't use redhat, fedora, or their kernel binaries.

> They you are limited to inode based auditing. Or maybe if you put the things 
> you have to watch onto one partition, you can use devmajor and minor. I'd try 
> to move to a 2.6.18 kernel with the latest audit package.

> -Steve

Steve,
If I'm reading this correctly, you're telling me that the 1.0.14 auditd that ships with RHEL4u3 is immature, at best.  Does this mean that I will never get support for the dispatcher directive in /etc/auditd.conf?  I was hoping to use the development Snare scripts that Leigh put together, mainly for a unified, centralization of our audit trails, but it doesn't work if the dispatcher support option is missing.

I understand that file watching will not be an auditable event and that I'll have to filter out a lot of false positives.  I just want to get centralized auditing working without have to script a bunch of it myself.

Thanks!
Charlie Todd
Ball Aerospace & Technologies Corp.
ctodd- at -ball -com

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2006-11-14  4:17 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-10-11 11:49 Audit-1.0.14 Boyce, Kevin P. (Melbourne, FL)
2006-10-11 12:24 ` Audit-1.0.14 Steve Grubb
  -- strict thread matches above, loose matches on Subject: below --
2006-11-09 19:56 Audit-1.0.14 Todd, Charles
2006-11-13 14:19 ` Audit-1.0.14 Steve Grubb
2006-11-14  4:17   ` Audit-1.0.14 Todd, Charles

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox