public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Auditd Troubleshooting
@ 2019-06-06 13:31 Boyce, Kevin P [US] (AS)
  2019-06-06 13:54 ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Boyce, Kevin P [US] (AS) @ 2019-06-06 13:31 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 628 bytes --]

Dear List,

It would be really great if there were an audit rule hit counter like many firewalls have when IP traffic passes through a filter rule.

This would be beneficial for finding rules that might not be working the as intended (to fix user implementation problems).

I'm thinking it would be a switch option on auditctl -l (maybe -h for hitcount).  This would list each rule that the kernel has, and how many times since auditd started that an event matched the rule.

Is this within the realm of feasibility?  Does this function exist maybe elsewhere in the audit suite (like aureport)?

Kind Regards,
Kevin

[-- Attachment #1.2: Type: text/html, Size: 2732 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-06-06 15:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-06-06 13:31 Auditd Troubleshooting Boyce, Kevin P [US] (AS)
2019-06-06 13:54 ` Steve Grubb
2019-06-06 15:01   ` EXT :Re: " Boyce, Kevin P [US] (AS)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox