Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Why exclude unset auid in STIG rules
@ 2016-05-11 18:32 Wyatt, Curtis
  0 siblings, 0 replies; 6+ messages in thread
From: Wyatt, Curtis @ 2016-05-11 18:32 UTC (permalink / raw)
  To: linux-audit@redhat.com

I don't understand why the STIG audit rules have -F auid!=4294967295 in it.  If auid is unset, why wouldn't you still want to see the events in the logs?

Curtis

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2016-05-11 20:43 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <A08CED02BC8EFC4B89CE0E0B16F995C4389B9DF6@azrc4sazmsg10.rc4s.com>
2016-05-11 18:34 ` Why exclude unset auid in STIG rules Steve Grubb
2016-05-11 18:40   ` Wyatt, Curtis
2016-05-11 19:10     ` Steve Grubb
2016-05-11 20:16       ` Wyatt, Curtis
2016-05-11 20:43         ` Warron S French
2016-05-11 18:32 Wyatt, Curtis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox