linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Excluding stat syscall logging for specific path
@ 2016-04-29 17:56 Vincas Dargis
  2016-04-29 18:00 ` Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Vincas Dargis @ 2016-04-29 17:56 UTC (permalink / raw)
  To: linux-audit

Hi,

When playing/learning with auditd, I wanted to log events when apache fails to access file.

Here's the rules I used in Debian Wheezy (same on Jessie and and current latest Testing):

-a exit,never -F arch=b64 -S stat -F path=/var/www/server-status -k web
-a exit,always -F arch=b64 -S stat -F uid=www-data -F success=0 -k web

/var/www/server-status file is non-existant, it's just alias for accessing mod_status information ( 
http://.../server-status path is accessed by munin regularly) so I wanted to minimise noise by that exit,never rule.

But I can't get it work.

I have more in-depth post in Debian forums [1] if that helps, but in short, should this work in general?

Thanks!

[1] http://forums.debian.net/viewtopic.php?f=5&t=128092

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-04-29 19:05 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-04-29 17:56 Excluding stat syscall logging for specific path Vincas Dargis
2016-04-29 18:00 ` Steve Grubb
2016-04-29 18:16   ` Vincas Dargis
2016-04-29 18:48     ` Steve Grubb
2016-04-29 19:05       ` Vincas Dargis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).