linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Excluding few executable from audit.rules  in redhat6.5
@ 2014-11-17 15:02 Tilden Doran D
  2014-11-17 15:30 ` Steve Grubb
  0 siblings, 1 reply; 10+ messages in thread
From: Tilden Doran D @ 2014-11-17 15:02 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 1499 bytes --]

Hi All,

I am new to Redhat Audit logging.
Our Server Configurations:  Redhat 6.5 OS and Oracle 11g ,  and SELinux is enabled.

We are getting lots of logs messages  in /var/log/messages.

type=SYSCALL msg=audit(1416235337.083:2109222): arch=c000003e syscall=90 success=yes exit=0 a0=7f52ae9f1a20 a1=3ff a2=ffffffffffffff88 a3=fffffffffffffff0 items=1 ppid=1 pid=46859 auid=500 uid=345 gid=345 euid=345 suid=345 fsuid=345 egid=345 sgid=345 fsgid=345 tty=(none) ses=28 comm="ohasd.bin" exe="/opt/oracle_homes/oracle/grid/11.2.0/bin/ohasd.bin" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="perm_mod"
type=PATH msg=audit(1416235337.083:2109222): item=0 name="/opt/oracle_homes/oracle/grid/11.2.0/auth/ohasd/dl360x3364/A7679703" inode=4718596 dev=fd:00 mode=041755 ouid=345 ogid=345 rdev=00:00 obj=unconfined_u:object_r:usr_t:s0 nametype=NORMAL


Later we found and removed message type "CWD", but still we are  getting lot of logs.

And also found that the below mentioned executable are creating the problem.

13351. 11/16/2014 18:11:34 /opt/oracle_homes/oracle/grid/11.2.0/bin/ohasd.bin (none) ? 500 1599360
13352. 11/16/2014 18:11:34 /opt/oracle_homes/oracle/rdbms/11.2.0/bin/oracle (none) ? 500 1599354
13353. 11/16/2014 18:11:34 /opt/oracle_homes/oracle/grid/11.2.0/bin/oraagent.bin (none) ? 500 1599361

Can you  please help me in excluding the above mentioned Executable `s in the audit. rules files .

Thanks in advance.


--Tilden
Ericsson AB




[-- Attachment #1.2: Type: text/html, Size: 4256 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2014-11-19 15:31 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-11-17 15:02 Excluding few executable from audit.rules in redhat6.5 Tilden Doran D
2014-11-17 15:30 ` Steve Grubb
2014-11-17 16:14   ` LC Bruzenak
2014-11-17 16:42     ` Steve Grubb
2014-11-17 17:09       ` Steve Grubb
2014-11-18 10:22         ` Tilden Doran D
2014-11-18 15:25           ` Steve Grubb
2014-11-19  5:38             ` Tilden Doran D
2014-11-19 15:31               ` Steve Grubb
2014-11-18 10:10   ` Tilden Doran D

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).