public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Example
@ 2008-09-23 16:18 Fulda, Paul (Space Technology)
  2008-09-23 16:23 ` Example Fulda, Paul (Space Technology)
  2008-09-24 11:34 ` Example Steve Grubb
  0 siblings, 2 replies; 3+ messages in thread
From: Fulda, Paul (Space Technology) @ 2008-09-23 16:18 UTC (permalink / raw)
  To: Linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 357 bytes --]

Can someone give me an example of how to audit the "date" command in the
audit.rules file.  I would like for it to report only failures for a
user using the command.  Root using the command would report nothing.  I
can get this working for file watches but not for executables using:

-a exit,always  -w /etc/shadow -S open -F success!=1


Thanks!

[-- Attachment #1.2: Type: text/html, Size: 827 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2008-09-24 11:34 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-09-23 16:18 Example Fulda, Paul (Space Technology)
2008-09-23 16:23 ` Example Fulda, Paul (Space Technology)
2008-09-24 11:34 ` Example Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox