public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* How to make sure a specific event is logged with thge proper message type?
@ 2015-07-06 14:02 Alarie, Maxime
  2015-07-06 15:08 ` Boyce, Kevin P (AS)
  2015-07-06 16:01 ` Steve Grubb
  0 siblings, 2 replies; 4+ messages in thread
From: Alarie, Maxime @ 2015-07-06 14:02 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 235 bytes --]

Hi,

I have this rule in audit.rules : -w /usr/sbin/useradd -p x -k user_modification

When I add a user, and do a ausearch -m ADD_USER   I get 0 match.  Am I doing something wrong here?  I am using version 1.8.




Thanks


[-- Attachment #1.2: Type: text/html, Size: 2799 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2015-07-06 16:01 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-07-06 14:02 How to make sure a specific event is logged with thge proper message type? Alarie, Maxime
2015-07-06 15:08 ` Boyce, Kevin P (AS)
2015-07-06 15:29   ` Alarie, Maxime
2015-07-06 16:01 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox