public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* auditing activity where uid==0
@ 2009-10-19 15:02 Rich Whitcroft
  2009-10-19 15:14 ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: Rich Whitcroft @ 2009-10-19 15:02 UTC (permalink / raw)
  To: linux-audit

Hi,

Here's my current rule, which is working, but is producing a lot of 
extra log that I'd like to suppress:

-a entry,always -S execve -F euid=0

I'm wondering if there's a way to limit this to only audit events that 
happen from a real tty, e.g. a human user. I'm getting lots of 
extraneous chatter from sshd, automount, and cron, all of which are from 
tty=(none), but I'm not sure it's possible to filter on tty...

Thanks

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2009-12-04 14:35 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-19 15:02 auditing activity where uid==0 Rich Whitcroft
2009-10-19 15:14 ` Steve Grubb
2009-12-04 11:08   ` Trevor Vaughan
2009-12-04 14:35     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox