public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* (no subject)
@ 2008-01-12 13:45 Abhishek Gupta
  2008-01-12 14:55 ` Steve Grubb
  0 siblings, 1 reply; 13+ messages in thread
From: Abhishek Gupta @ 2008-01-12 13:45 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 426 bytes --]

msg=audit(1116360555.329:2401771).

How to interpret above message?what does 1116360555,329,2401771 means here?
By looking at this type of audit message how can i interpret all the things
related to a particular process?
If i want to trace all syscalls called by particular process how to do that
without using ausearch(means by looking at above type messages)
how can i obtain strace output by this this auditing subsystem ?

[-- Attachment #1.2: Type: text/html, Size: 499 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 13+ messages in thread
* (no subject)
@ 2007-11-02 16:21 Bill Tangren
  0 siblings, 0 replies; 13+ messages in thread
From: Bill Tangren @ 2007-11-02 16:21 UTC (permalink / raw)
  To: Linux-audit

I am running audit-1.0.15-3.EL4 on a RHEL ES 4 system, fully patched. I am
trying to learn the meaning of the output of aureport. For example, if I
want to look at failed events, could you tell me what the following means?
That is, how do I know from this what is failing, and why?



[root@doggett ~]# /sbin/aureport -e --failed -ts yesterday 00:00:00 -te
today 00:00:00

Event Report
===========================
# date time event type auid
===========================
1. 11/01/2007 12:00:00 AM 5844794 SYSCALL -1



TIA,
Bill Tangren

^ permalink raw reply	[flat|nested] 13+ messages in thread
* (no subject)
@ 2007-08-18 17:02 Henning, Arthur C. (CSL)
  0 siblings, 0 replies; 13+ messages in thread
From: Henning, Arthur C. (CSL) @ 2007-08-18 17:02 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 695 bytes --]

RHEL 5

Have two events having difficulty capturing or reviewing with the audit
sub-system.

1. su - "non_existent_account". Using the nispom.rules provided by audit
1.5.6-1. Using various ausearch parameters, am unable to find a
corresponding failure when attempting to "su" to a non-existent account.

2. Non-privileged user attempting to change the date/time on the server.
Of course the user fails to be able to do so, but am unable to capture
or review the event.

Not sure if these are audit rule configuration or search unknowns or
audit sub-system limitations.

Thank you
Art Henning (CSL) 
Enterprise IT Solutions
Northrop Grumman Corporation
art.henning@ngc.com


[-- Attachment #1.2: Type: text/html, Size: 1419 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 13+ messages in thread
* (no subject)
@ 2007-05-24 14:03 Kirkwood, David A.
  0 siblings, 0 replies; 13+ messages in thread
From: Kirkwood, David A. @ 2007-05-24 14:03 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 276 bytes --]

How do I place a watch on files that are being rotated? For example: I
want to audit the audit logs themselves , and when they are rotated I
need to watch the new audit log that is created as well as the rotated
logs. 

 

Thanks,

 

David A. Kirkwood



 


[-- Attachment #1.2: Type: text/html, Size: 2124 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 13+ messages in thread
[parent not found: <000301c78399$1924de30$656fa8c0@centrify.com>]
* (no subject)
@ 2007-03-15 19:42 Kirkwood, David A.
  2007-03-15 21:15 ` Bill Tangren
  0 siblings, 1 reply; 13+ messages in thread
From: Kirkwood, David A. @ 2007-03-15 19:42 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 380 bytes --]

When I view the events related to xscreensaver for a locked screen  I
get 2 separate audit entries, one for a failure and 1 as a success. Both
have the same uid, euid, etc. Actually, the entries are exactly the same
except for the event number and the success outcome. I  have the
xscreensaver executable set -rwsr-xr-x. 

 

Thanks,

 

David A. Kirkwood



 


[-- Attachment #1.2: Type: text/html, Size: 2237 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 13+ messages in thread
* (no subject)
@ 2006-05-03 17:21 Kirkwood, David A
  2006-05-03 17:31 ` Steve Grubb
  0 siblings, 1 reply; 13+ messages in thread
From: Kirkwood, David A @ 2006-05-03 17:21 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 101 bytes --]

I don't see any timestamps on audit events. How can I bracket events between
to dates /times?

 

 


[-- Attachment #1.2: Type: text/html, Size: 1610 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2008-01-12 14:55 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-01-12 13:45 (no subject) Abhishek Gupta
2008-01-12 14:55 ` Steve Grubb
  -- strict thread matches above, loose matches on Subject: below --
2007-11-02 16:21 Bill Tangren
2007-08-18 17:02 Henning, Arthur C. (CSL)
2007-05-24 14:03 Kirkwood, David A.
     [not found] <000301c78399$1924de30$656fa8c0@centrify.com>
2007-04-20 22:13 ` paul moore
2007-04-20 23:32   ` Steve Grubb
     [not found]     ` <000701c783ab$6be710e0$656fa8c0@centrify.com>
2007-04-21  0:24       ` paul moore
2007-04-23 13:46         ` Steve Grubb
2007-03-15 19:42 Kirkwood, David A.
2007-03-15 21:15 ` Bill Tangren
2006-05-03 17:21 Kirkwood, David A
2006-05-03 17:31 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox