public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* user audits
@ 2010-12-03 15:40 LC Bruzenak
  2010-12-03 15:54 ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: LC Bruzenak @ 2010-12-03 15:40 UTC (permalink / raw)
  To: Linux Audit

Steve,

Would there be any issue with adding a couple new trusted_application
event types? Would any kernel mods be needed to support this?

The reason I ask is because I'd like to process some event types
differently on the back end (the aggregator) and if I could easily
identify those types it would make life easier.

Some trusted_application events are for recording "bad" security issues,
some for "good", etc. and I'd like to easily differentiate those. 

I can put something inside the event text but if possible would prefer a
couple different types, like trusted_app1, trusted_app2, etc.

Thx,
LCB

-- 
LC (Lenny) Bruzenak
lenny@magitekltd.com

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-12-03 16:25 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-12-03 15:40 user audits LC Bruzenak
2010-12-03 15:54 ` Steve Grubb
2010-12-03 16:12   ` LC Bruzenak
2010-12-03 16:25     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox