public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Adding enterprise capability - an includeConfig directive for audit.rules?
@ 2013-03-27  9:38 Burn Alting
  2013-04-02 18:03 ` Steve Grubb
  0 siblings, 1 reply; 11+ messages in thread
From: Burn Alting @ 2013-03-27  9:38 UTC (permalink / raw)
  To: Linux-Audit Mailing List

All,

Has anyone considered allowing an includeConfig statement for
audit.rules (or auditd.conf if need be)?

The action would be to, at that point in the parse (or the end of the
file, if auditd.conf holds the directive), open the nominated directory
and any files within, and parse them.

The idea is to allow for localization of audit. At an enterprise level
one would deploy the common, corporate set of rules
in /etc/audit/audit.rules. Should a local system need additional rules
such as tailored file watches, workstation or capability specific
monitoring, these could appear in files in the includeConfig directory.
That way, distribution mechanisms such as puppet, rpm satellite server,
apt repositories, etc can maintain the corporate set of rules without
changing localized configurations on updates.

I'm happy to author this.

Regards
Burn Alting

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2013-04-24 20:37 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-03-27  9:38 Adding enterprise capability - an includeConfig directive for audit.rules? Burn Alting
2013-04-02 18:03 ` Steve Grubb
2013-04-03 10:37   ` Burn Alting
2013-04-03 11:42     ` Steve Grubb
2013-04-03 13:19       ` EXT :Re: " Boyce, Kevin P. (AS)
2013-04-03 20:19         ` Burn Alting
2013-04-07 11:16           ` Burn Alting
2013-04-18 13:49             ` Steve Grubb
2013-04-18 21:23               ` Burn Alting
2013-04-19 10:53                 ` Steve Grubb
2013-04-24 20:37                   ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox