public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Exclude /usr/libexec/mysqld from audit.rules
@ 2013-12-06 20:34 Derek Warner
  2013-12-09 14:32 ` Steve Grubb
  0 siblings, 1 reply; 8+ messages in thread
From: Derek Warner @ 2013-12-06 20:34 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1114 bytes --]

ALCON,

We have a Centos machine running Centos 6 and it uses mysql. When a
standard user operates the system, our /var/log/messages gets filled up
with around 2gb of audit data rather quickly. Here is the audit.

Dec  6 15:22:12 aaa-bbb audispd: node=aaa-bbb.ccc.ddd.eee type=SYSCALL
msg=audit(1386361331.932:3572423): arch=c000003e syscall=142 success=no
exit=-22 a0=1f46 a1=7f5e6357e290 a2=d3b6f8 a3=1f68 items=0 ppid=2518
pid=8006 auid=4294967295 uid=496 gid=492 euid=496 suid=496 fsuid=496
egid=492 sgid=492 fsgid=492 tty=(none) ses=4294967295 comm="mysqld"
exe="/usr/libexec/mysqld" key=(null)

I have tried the following:

-a exit,never -F path=/usr/libexec/mysqld

When using "-F" I noticed in one RHEL forum someone used -F exe=

However in CENTOS exe is not a recognized field when using -F

We do not wish to audit this data, can someone please help me exclude the
audit?

V/R

Derek Warner – CISSP-ISSEP

Information System Security Engineer

Riptide Software

w- 321-296-0068 x 136

c-  407-716-9223

derek.warner@riptidesoftware.com

derek.a.warner@us.army.mil

[-- Attachment #1.2: Type: text/html, Size: 1911 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2013-12-10 17:54 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-12-06 20:34 Exclude /usr/libexec/mysqld from audit.rules Derek Warner
2013-12-09 14:32 ` Steve Grubb
2013-12-09 15:20   ` Derek Warner
2013-12-09 15:34     ` Steve Grubb
2013-12-09 15:59       ` Derek Warner
2013-12-09 15:34   ` Derek Warner
2013-12-09 16:22     ` Steve Grubb
2013-12-10 17:54       ` Derek Warner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox