From: Steve Grubb <sgrubb@redhat.com>
To: Eric Paris <eparis@redhat.com>, pmoore@redhat.com
Cc: Richard Guy Briggs <rgb@redhat.com>, linux-audit@redhat.com
Subject: Re: [RFC][PATCH] audit: log join and part events to the read-only multicast log socket
Date: Wed, 22 Oct 2014 10:30:43 -0400 [thread overview]
Message-ID: <2321586.r0h2DRl0fr@x2> (raw)
In-Reply-To: <1413930629.30946.68.camel@localhost>
On Tuesday, October 21, 2014 06:30:29 PM Eric Paris wrote:
> On Tue, 2014-10-21 at 17:08 -0400, Richard Guy Briggs wrote:
> > On 14/10/21, Steve Grubb wrote:
> > > audit_log_task_info logs too much information for typical use. There are
> > > times when you might want to know everything about what's connecting.
> > > But in this case, we don't need anything about groups, saved uids,
> > > fsuid, or ppid.
> > >
> > > Its a shame we don't have a audit_log_task_info_light function which
> > > only
> > > records:
> > >
> > > pid= auid= uid= subj= comm= exe= ses= tty=
> >
> > We already have audit_log_task() which gives:
> > auid=
> > uid=
> > gid=
> > ses=
> > subj=
> > pid=
> > comm=
> > exe=
> >
> > This is missing tty=, but has gid=. Can we please use that function
> > instead and add tty=? And while we are at it, refactor
> > audit_log_task_info() to call audit_log_task()?
> >
> > Is this standard set above what should be used for certain classes of
> > log messages?
> >
> > Yes, it will be in a different order because we don't have a canonical
> > order yet. Can we accept two orders of keywords so we can start
> > canonicalizing, please?
>
> I've always hated the fact that we include this in ANY current audit
> message. I truly believe we need two new record types.
>
> AUDIT_PROCESS_INFO
> AUDIT_EXTENDED_PROCESS_INFO
It'll eat at least 60 bytes per record and its its an aggregated log, then
throw in the length of the system names. Disk space is at a premium. We want
as many records as possible in the logging partition. Also, this will
translate into more network traffic, more buffers needed in the kernel queue,
more buffers in audispd and remote logging.
> What does my UID have to do with a syscall? Why is it in the record?
To save space. But also because it may be relevant to whatever is happening.
-Steve
next prev parent reply other threads:[~2014-10-22 14:30 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-10-07 18:23 [RFC][PATCH] audit: log join and part events to the read-only multicast log socket Richard Guy Briggs
2014-10-07 19:03 ` Eric Paris
2014-10-07 19:39 ` Richard Guy Briggs
2014-10-07 22:06 ` Paul Moore
2014-10-11 15:42 ` Steve Grubb
2014-10-11 20:00 ` Paul Moore
2014-10-21 16:41 ` Richard Guy Briggs
2014-10-21 19:56 ` Steve Grubb
2014-10-21 21:08 ` Richard Guy Briggs
2014-10-21 21:40 ` Steve Grubb
2014-10-29 20:23 ` Richard Guy Briggs
2014-10-21 22:30 ` Eric Paris
2014-10-21 23:14 ` Paul Moore
2014-10-22 1:18 ` Richard Guy Briggs
2014-10-22 14:30 ` Steve Grubb [this message]
2014-10-21 22:30 ` Paul Moore
2014-10-22 1:24 ` Richard Guy Briggs
2014-10-22 13:34 ` Paul Moore
2014-10-29 21:09 ` Richard Guy Briggs
2014-10-22 14:34 ` Steve Grubb
2014-10-22 14:25 ` Steve Grubb
2014-10-22 14:30 ` Eric Paris
2014-10-22 14:36 ` Steve Grubb
2014-10-22 15:08 ` Eric Paris
2014-10-22 15:12 ` Eric Paris
2014-10-22 15:51 ` LC Bruzenak
2014-10-22 16:24 ` Steve Grubb
2014-10-22 18:18 ` Eric Paris
2014-10-22 19:36 ` LC Bruzenak
2014-10-22 20:00 ` Steve Grubb
2014-10-22 15:28 ` Paul Moore
2014-10-22 17:56 ` Steve Grubb
2014-10-22 20:06 ` Paul Moore
2014-10-22 20:34 ` LC Bruzenak
2014-10-22 20:44 ` Paul Moore
2014-10-22 21:11 ` LC Bruzenak
2014-10-22 21:29 ` Paul Moore
2014-10-23 14:19 ` LC Bruzenak
2014-10-23 19:08 ` Paul Moore
2014-10-22 20:39 ` Steve Grubb
2014-10-22 21:00 ` Paul Moore
2014-10-22 21:18 ` Steve Grubb
2014-10-23 19:15 ` Paul Moore
2014-10-30 14:55 ` Richard Guy Briggs
2014-10-30 14:48 ` Typo in AUDIT_FEATURE_CHANGE events [was: Re: [RFC][PATCH] audit: log join and part events to the read-only multicast log socket] Richard Guy Briggs
2014-10-30 15:10 ` Steve Grubb
2014-10-30 15:23 ` Richard Guy Briggs
2014-10-29 21:38 ` [RFC][PATCH] audit: log join and part events to the read-only multicast log socket Richard Guy Briggs
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2321586.r0h2DRl0fr@x2 \
--to=sgrubb@redhat.com \
--cc=eparis@redhat.com \
--cc=linux-audit@redhat.com \
--cc=pmoore@redhat.com \
--cc=rgb@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox