public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Excluding events by command
@ 2012-09-18 16:50 Laura Martín
  2012-09-18 16:59 ` Steve Grubb
  2012-09-18 17:29 ` Laura Martín
  0 siblings, 2 replies; 7+ messages in thread
From: Laura Martín @ 2012-09-18 16:50 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 767 bytes --]

Hi all,

I'm trying to exclude cron events from audit logging. I can't see how can I
do to only exclude this kind of entries:


----
time->Mon Sep 17 11:00:01 2012
type=PATH msg=audit(1347872401.521:5212): item=0
name="/etc/pam.d/system-auth" inode=33635 dev=fd:00 mode=0100644 ouid=0
ogid=0 rdev=00:00
type=CWD msg=audit(1347872401.521:5212):  cwd="/var/spool"
type=SYSCALL msg=audit(1347872401.521:5212): arch=c000003e syscall=2
success=yes exit=5 a0=2b5b7b627300 a1=0 a2=1b6 a3=0 items=1 ppid=11640
pid=1965 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
fsgid=0 tty=(none) ses=4294967295 comm="crond" exe="/usr/sbin/crond"
key=(null)
----

I didn't see any option to exclude events by 'exe' or 'comm' field.

Any hints?

Thanks in advance, Laura

[-- Attachment #1.2: Type: text/html, Size: 900 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2012-09-18 18:40 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-09-18 16:50 Excluding events by command Laura Martín
2012-09-18 16:59 ` Steve Grubb
2012-09-18 17:12   ` Peter Moody
2012-09-18 17:29     ` Steve Grubb
2012-09-18 17:31       ` Peter Moody
2012-09-18 18:40         ` Steve Grubb
2012-09-18 17:29 ` Laura Martín

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox