Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* audit-tools and SUDO
@ 2016-05-10 12:31 Warron S French
  2016-05-10 12:52 ` Burn Alting
  0 siblings, 1 reply; 9+ messages in thread
From: Warron S French @ 2016-05-10 12:31 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 1379 bytes --]

Good morning everyone,

I am working on an environment where I have managed to get centralized audit logging to work - roughly 95% properly on six (6) CentOS-6.7 workstations and a single (1) CentOS-6.7 server.

I have two problems though; and they seem somewhat minor:


1.       The audit events being captured don't seem to be tied to any given node (so that I can perform ausearch --node hostName, or aureport), that's the first issue.

2.       The second issue is that I need to configure sudo to enable my Special Security Team with the ability to perform their duties using the aureport and the ausearch commands, but I get an error that appears to be based on permissions.

I am hoping that you guys can steer me in the correct direction; and I can update my documentation to be even a little more thorough.

Scenario2, might be more of a membership issue now that I think about it; so please disregard as I think this is some weird 389-ds issue.

I am hoping though that someone can suggest a reason why, when I look directly at the content of the /var/log/audit/audit.log I am not see any references to node=hostname1, hostname2 .. hostnameN?  Maybe I did misconfigure something, but I followed my own instructions to the "T" and they didn't produce this issue.



Thank you in advance for your precious time sincerely,

Warron French, MBA, SCSA

[-- Attachment #1.2: Type: text/html, Size: 6118 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2016-05-10 17:46 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-05-10 12:31 audit-tools and SUDO Warron S French
2016-05-10 12:52 ` Burn Alting
2016-05-10 13:07   ` Warron S French
2016-05-10 13:25   ` Steve Grubb
2016-05-10 13:44     ` Warron S French
2016-05-10 14:31       ` Steve Grubb
2016-05-10 15:25         ` Warron S French
2016-05-10 15:45           ` Steve Grubb
2016-05-10 17:46             ` Warron S French

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox