public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* linux auditd: Not getting log for chmod syscall
@ 2012-01-13  4:52 bharat gupta
  2012-01-13 20:04 ` Steve Grubb
  0 siblings, 1 reply; 6+ messages in thread
From: bharat gupta @ 2012-01-13  4:52 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 566 bytes --]

Hi,

I am using redhat 6, and trying to create logs for some system call using
the rule given below:

*-a always,exit -F arch=b64  -S chmod -S fchmod -S fchmodat -F auid>=500
 -F auid!=4294967295 -k perm_mod*

After running command chmod i was not able to get any log, but when i used
strace command i have seen that syscall have been called.
I also checked that auditd service is running properly.
May you guide me why i am not able to get any log message.
i also checked by writting rule for 32  bit, but problem still not resolved.

-- 
Bharat Gupta
IIT -Roorkee

[-- Attachment #1.2: Type: text/html, Size: 802 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2012-01-24 16:03 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-01-13  4:52 linux auditd: Not getting log for chmod syscall bharat gupta
2012-01-13 20:04 ` Steve Grubb
2012-01-18 11:10   ` bharat gupta
2012-01-18 12:10     ` Marcelo Cerri
     [not found]       ` <CAKYigEAYpkm99o1XbhEAz0CrsMFSLBQdp8cY0TCAZxpVzZ1DMw@mail.gmail.com>
     [not found]         ` <4F17FB57.9010804@linux.vnet.ibm.com>
     [not found]           ` <CAKYigEDBechU7a=fdf0_aPuK01k2yESx5J7SWcAt2X6qn2pzvA@mail.gmail.com>
     [not found]             ` <4F180497.2080900@linux.vnet.ibm.com>
     [not found]               ` <CAKYigEDrCdWVhT7wX4260xe2sUtkm0dd0DuhPfuhHvq98on41Q@mail.gmail.com>
     [not found]                 ` <4F1808F7.1010709@linux.vnet.ibm.com>
     [not found]                   ` <CAKYigEA1eti=0xsgKiyzOavHg6DnjF4pVLGbCj4HvQZ4ViieOw@mail.gmail.com>
     [not found]                     ` <CAKYigEC8zaqkOAOZK6YNzdLqK+9fXbFrVS_0jA=CVsdM9qyMmg@mail.gmail.com>
     [not found]                       ` <4F1EA802.1090003@linux.vnet.ibm.com>
     [not found]                         ` <CAKYigEC-Av7f+0n2zTADiEdNdWzt3QcOC13SnsUn2QodUytWng@mail.gmail.com>
     [not found]                           ` <4F1ECDD2.5040907@linux.vnet.ibm.com>
2012-01-24 15:30                             ` Fwd: " bharat gupta
2012-01-24 16:03                               ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox