* Significant performance hit auditing system account actions?
@ 2015-05-14 19:24 leam hall
2015-05-14 20:04 ` Steve Grubb
0 siblings, 1 reply; 2+ messages in thread
From: leam hall @ 2015-05-14 19:24 UTC (permalink / raw)
To: linux-audit
[-- Attachment #1.1: Type: text/plain, Size: 434 bytes --]
Some security requirements include auditing events by users and root. So
the line might include something like:
-F auid=0 -F auid>=500 -F auid!=4294967295
My question is, if you don't include that phrase will the audit system
still get everything and not incur a serious performance hit. Effectively
it will audit everything for users 1-499, the usual system accounts.
Leam
--
Mind on a Mission <http://leamhall.blogspot.com/>
[-- Attachment #1.2: Type: text/html, Size: 670 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Significant performance hit auditing system account actions?
2015-05-14 19:24 Significant performance hit auditing system account actions? leam hall
@ 2015-05-14 20:04 ` Steve Grubb
0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2015-05-14 20:04 UTC (permalink / raw)
To: linux-audit
On Thursday, May 14, 2015 03:24:16 PM leam hall wrote:
> Some security requirements include auditing events by users and root. So
> the line might include something like:
>
> -F auid=0 -F auid>=500 -F auid!=4294967295
The fields will be "anded". You cannot simultaneously have auid of 0 and >=500.
So, you won't get any events.
> My question is, if you don't include that phrase will the audit system
> still get everything and not incur a serious performance hit. Effectively
> it will audit everything for users 1-499, the usual system accounts.
Typically the requirements read as audit root user actions - which is covered
by TTY auditing. Everything else is covered by the other rules.
-Steve
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2015-05-14 20:04 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-05-14 19:24 Significant performance hit auditing system account actions? leam hall
2015-05-14 20:04 ` Steve Grubb
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).