public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* New to audit. Need help configuring audit to meet NISPOM req's
@ 2007-02-27  8:25 Fields, Randy (Space Technology)
  2007-02-28  3:00 ` Steve Grubb
  0 siblings, 1 reply; 13+ messages in thread
From: Fields, Randy (Space Technology) @ 2007-02-27  8:25 UTC (permalink / raw)
  To: linux-audit

Hello All,
I'm a linux administrator and computer security rep with a small NIS domain all running RHEL 4.4 ES on x86 platforms. 
I'm looking for any help, scripts, or just copies of configuration files so that I can learn from your examples while studying the man pages.

Here are the list of items that I need to accomplish and I greatly appreciate any help that you can provide.
1) I need to configure a test box to meet NISPOM audit requirements. (any examples of /etc/auditd.conf and /etc/audit.rules would be great)
2) Then test it by acting as a user and trying to access files such as /etc/passwd and /etc/shadow.
3) Then report that data to prove to auditors that the tool is collecting the events.

Thank you in advance. Feel free to e-mail me directly to avoid any unwanted cluttering of the message boards.
Randy Fields
randy.fields@ngc.com 

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2007-03-01  2:41 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-02-27  8:25 New to audit. Need help configuring audit to meet NISPOM req's Fields, Randy (Space Technology)
2007-02-28  3:00 ` Steve Grubb
2007-02-28 11:02   ` Johnston Mark (UK)
2007-02-28 11:07     ` Syscalls Johnston Mark (UK)
2007-02-28 11:43       ` Syscalls Steve Grubb
2007-02-28 12:23         ` Syscalls Johnston Mark (UK)
2007-02-28 12:25           ` Syscalls Marcus Meissner
2007-02-28 13:28           ` Syscalls Steve Grubb
2007-02-28 14:53             ` Syscalls Valdis.Kletnieks
2007-02-28 15:25               ` Syscalls Steve Grubb
2007-02-28 19:24                 ` Syscalls James W. Hoeft
2007-02-28 15:17             ` Syscalls Steve Grubb
2007-03-01  2:41           ` Syscalls Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox