From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Cc: intrigeri <intrigeri@debian.org>, 759604@bugs.debian.org
Subject: Re: Bug#759604: Any problem with making auditd log readable by the adm group?
Date: Wed, 11 May 2016 08:36:44 -0400 [thread overview]
Message-ID: <4396759.amBRPDjSgs@x2> (raw)
In-Reply-To: <ad8f4cd5-a921-c66d-881b-2b00ec4f07cc@debian.org>
On Wednesday, May 11, 2016 09:55:33 AM Laurent Bigonville wrote:
> Le 09/05/16 à 21:07, intrigeri a écrit :
> > Hi,
>
> Hey,
>
> > in Debian, the convention for many log files is to make them readable
> > by members of the adm group. We're considering doing the same for the
> > auditd logs, in order to make apparmor-notify work out-of-the-box.
>
> Shouldn't apparmor-notify use the audispd to get the events instead of
> parsing directly the logs?
If this is a realtime event analysis tool, then yes. (The original question I
thought was if adding the adm group to let admins search audit logs would hurt
anything.) There are two ways that you can get the events. One way is to
enable the af_unix plugin and read off of the unix socket. The other way is to
make a plugin for which there is skeleton code here:
https://github.com/linux-audit/audit-userspace/tree/master/contrib/plugin
> I'm not objecting changing the permissions in debian, but I'm wondering
> if it shouldn't be better to do it like that, I think that the
> setroubleshoot (a SELinux troubleshooting service used in RHEL/Fedora)
> is doing it like that.
That is correct.
-Steve
prev parent reply other threads:[~2016-05-11 12:36 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-05-09 19:07 Bug#759604: Any problem with making auditd log readable by the adm group? intrigeri
2016-05-09 19:33 ` Steve Grubb
2016-05-10 9:07 ` Bug#759604: " intrigeri
2016-05-11 7:55 ` Laurent Bigonville
2016-05-11 12:36 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4396759.amBRPDjSgs@x2 \
--to=sgrubb@redhat.com \
--cc=759604@bugs.debian.org \
--cc=intrigeri@debian.org \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox