From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: prelude events Date: Mon, 25 Aug 2008 16:41:47 -0400 Message-ID: <200808251641.47803.sgrubb@redhat.com> References: <1219695605.7022.807.camel@homeserver> <1219695875.7022.811.camel@homeserver> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <1219695875.7022.811.camel@homeserver> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Monday 25 August 2008 16:24:35 LC Bruzenak wrote: > I think I just saw the answer in the audisp-prelude man page: > ... > -w /etc/shadow -p wa > > =C2=A0 =C2=A0 =C2=A0 =C2=A0and you want idmef alerts on this, you need = to add -k > ids-file-med =C2=A0or something appropriate to signal =C2=A0to =C2=A0th= e =C2=A0plugin > =C2=A0 =C2=A0 =C2=A0 =C2=A0that =C2=A0this =C2=A0message is for it. Yes, you'd add -k ids-file- and the one of: info, low, med, or high=20 depending on how severe you consider this access. -Steve