public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Linux Audit Framework question
@ 2012-06-20 11:04 Jan
  2012-06-25 12:01 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Jan @ 2012-06-20 11:04 UTC (permalink / raw)
  To: linux-audit@redhat.com

Hello,

I write you because i do not know how to go further without solving my problem.
When a user switches from username to root using sudo su - this action is audited by LAF but since that change the user-id in the LAF logfile is 0 for root user. If my user uses chmod afterwords to change file permissions i can not see which user did the change because user-id is 0 and the auditid is always 4294967295.
Can you tell me how it is possible to trace the user after switching to root ??


Thanks in advance,
Jan

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2012-06-25 12:01 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-06-20 11:04 Linux Audit Framework question Jan
2012-06-25 12:01 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox