public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Jonathan Abbey <jonabbey@arlut.utexas.edu>
To: Steve Grubb <sgrubb@redhat.com>
Cc: linux-audit@redhat.com, "Thomas,
	Daniel J." <Daniel.Thomas@jhuapl.edu>,
	"Wieprecht, Karen M." <Karen.Wieprecht@jhuapl.edu>
Subject: Re: Tools for reviewing audit logs ?
Date: Wed, 13 Dec 2006 10:36:05 -0600	[thread overview]
Message-ID: <20061213163604.GB5162@arlut.utexas.edu> (raw)
In-Reply-To: <200612121729.04049.sgrubb@redhat.com>


[-- Attachment #1.1: Type: text/plain, Size: 2222 bytes --]

On Tue, Dec 12, 2006 at 05:29:03PM -0500, Steve Grubb wrote:
| On Tuesday 12 December 2006 17:08, Wieprecht, Karen M. wrote:
| > Steve, I'm testing the RHEL4 audit 1.0.14 now with the sample capp.rules
| > , and I am generating data.  UGLY data.  I am wondering what
| > tools/GUIs/scripts people are using to look at this data.  
| 
| Some one published a perl based viewer to this mail list earlier this year. I 
| forget when. The aureport program was supposed to fill the immediate role of 
| breaking the data down into something a little more useful. My intentions are 
| to use that as the basis of a GUI based tool. The work is going slow and I'm 
| at the poiint of writing the parser library.

I'm guessing that was Leigh Purdie and the Snare team down at
Intersect Alliance in oz.  They had their own kernel auditing
framework that was hacked into earlier Linux kernels, and they have a
central logging server that provides a nice GUI for reviewing
color-coded audit records, in addition to a micro-web server that can
be hosted on the individual system being audited.

They've continued working on their toolset beyond the early work they
posted here earlier, and you can get it from

  http://www.intersectalliance.com/projects/SnareLinux/index.html

They are providing/recommending 'audit-1.2.1-1.i386.rpm' and
'audit-libs-1.2.1-1.i386.rpm' in addition to their
SnareLinux-1.0b7-1.i386.rpm, which provides the higher level analysis
tools, but I'm not sure why that's necessary, given that RHEL4 should
be providing those pieces (albeit with lower version numbers?) out of
the box.

 Jon

| > but I don't want to reproduce effort if there are nice scripts or  GUIs
| > available already. 
| 
| Aside from that perl based viewer and aureport, nothing I know of. It would be 
| helpful to me to know what your use cases/requirements are.
| 
| Thanks,
| -Steve

-- 
-------------------------------------------------------------------------------
Jonathan Abbey 				              jonabbey@arlut.utexas.edu
Applied Research Laboratories                 The University of Texas at Austin
GPG Key: 71767586 at keyserver pgp.mit.edu, http://www.ganymeta.org/workkey.gpg

[-- Attachment #1.2: Type: application/pgp-signature, Size: 189 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



  reply	other threads:[~2006-12-13 16:36 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20061211170024.6F9DF7337D@hormel.redhat.com>
2006-12-11 17:15 ` Linux-audit Digest, Vol 27, Issue 2 Thomas, Daniel J.
2006-12-11 18:20   ` Steve Grubb
2006-12-11 19:20     ` Thomas, Daniel J.
2006-12-11 19:33       ` Steve Grubb
2006-12-11 20:32     ` Wieprecht, Karen M.
2006-12-11 23:03       ` Steve Grubb
2006-12-12  2:16         ` Wieprecht, Karen M.
2006-12-12 22:08         ` Tools for reviewing audit logs ? Wieprecht, Karen M.
2006-12-12 22:29           ` Steve Grubb
2006-12-13 16:36             ` Jonathan Abbey [this message]
2006-12-13 17:21               ` Steve Grubb
2006-12-13 20:12                 ` Wieprecht, Karen M.
2006-12-13 16:45             ` Wieprecht, Karen M.
2006-12-13 17:09               ` Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20061213163604.GB5162@arlut.utexas.edu \
    --to=jonabbey@arlut.utexas.edu \
    --cc=Daniel.Thomas@jhuapl.edu \
    --cc=Karen.Wieprecht@jhuapl.edu \
    --cc=linux-audit@redhat.com \
    --cc=sgrubb@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox