From: Richard Guy Briggs <rgb@redhat.com>
To: Wojtczak Arkadiusz <arkadiusz.wojtczak@pkobp.pl>
Cc: "linux-audit@redhat.com" <linux-audit@redhat.com>
Subject: Re: Audit/Auditd/Audispd documentation
Date: Thu, 13 Nov 2014 09:37:26 -0500 [thread overview]
Message-ID: <20141113143726.GB9980@madcap2.tricolour.ca> (raw)
In-Reply-To: <4E8FFAAD447BD2478D75C4FAC3BD2CBF53CC98CB@M30SIEEXMX02.bank.ad.pkobp.pl>
On 14/11/13, Wojtczak Arkadiusz wrote:
> Hi,
> I've been searching for Audit documentation and stumbled upon following conversation:
> http://www.redhat.com/archives/linux-audit/2006-September/msg00081.html
>
> Has anything changed since 2006?
Just recently, Steve Grubb has published this document, which outlines
the desired format of audit log records with the aim of having it
included in the kernel source Documentation tree:
http://people.redhat.com/sgrubb/audit/audit-parse.txt
The existing records do not all follow this specification. There are
efforts to correct this, but some would break long-used parsers.
There have been several other discussions recently (last month or two)
that talk about specific and general issues. I'll let Steve answer in a
bit more detail.
> I need to write set of rules to correlate audit events from many systems. Following information would be very useful:
>
> 1) Event formats - What fields will be generated for particular event type? Which fields are common to all event types? What type of data will be in those fields (binary/encoded/ASCII/UNICODE)? What do those fields describe?
>
> 2) For all event types - description when (in what circumstances) are generated events of this type
>
> 3) How do DAC event types relate to AVC (which fields are common, which are not)
>
> Best regards,
> Arkadiusz Wojtczak
- RGB
--
Richard Guy Briggs <rbriggs@redhat.com>
Senior Software Engineer, Kernel Security, AMER ENG Base Operating Systems, Red Hat
Remote, Ottawa, Canada
Voice: +1.647.777.2635, Internal: (81) 32635, Alt: +1.613.693.0684x3545
next prev parent reply other threads:[~2014-11-13 14:37 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-13 14:20 Audit/Auditd/Audispd documentation Wojtczak Arkadiusz
2014-11-13 14:37 ` Richard Guy Briggs [this message]
2014-11-13 15:15 ` Steve Grubb
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141113143726.GB9980@madcap2.tricolour.ca \
--to=rgb@redhat.com \
--cc=arkadiusz.wojtczak@pkobp.pl \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox