public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Marko Weber | 8000 <weber@zbfmail.de>
To: linux-audit@redhat.com
Subject: suppress log entries, how?
Date: Wed, 01 Oct 2014 08:46:18 +0200	[thread overview]
Message-ID: <83161eeb858a1d542226038851db7789@zbfmail.de> (raw)


good morning list,

i installed auditd on my gentoo server.
installation runs without error, but on start i get this:

# /etc/init.d/auditd start
  * Starting auditd ...                                                   
                                                                          
                                                                          
                                               [ ok ]
touch: cannot touch '/var/lock/subsys/auditd': No such file or directory
  * Loading audit rules from /etc/audit/audit.rules

seems /var/lock/ `subsys/auditd` is missing.
that was easy to fix, but has to be repeated after every reboot.


in auditd.log i get entries like this:

type=NETFILTER_CFG msg=audit(1412022284.553:2446): table=mangle family=2 
entries=6
type=SYSCALL msg=audit(1412022284.553:2446): arch=c000003e syscall=54 
success=yes exit=0 a0=4 a1=0 a2=40 a3=1144850 items=0 ppid=2070 pid=2130 
auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 
tty=(none) ses=4294967295 comm="iptables" exe="/sbin/xtables-multi" 
key=(null)

i want to suppress these messages.
in my understanding of the man page i have to put such a rule into 
audit.rules:

-a exclude,never -F msgtype=NETFILTER_CFG , but this isnt working. the 
messages still appears.

my config of my fresh auditd install:

# First rule - delete all
# This is to clear out old rules, so we don't append to them.
-D

# Feel free to add below this line. See auditctl man page

-a exclude,never -F msgtype=NETFILTER_CFG

# The following rule would cause all of the syscalls listed to be 
ignored in logging.
-a exit,never -F arch=b32 -S read -S write -S open -S fstat -S mmap -S 
brk -S munmap -S nanosleep -S fcntl -S close -S dup2 -S rt_sigaction -S 
stat
-a exit,never -F arch=b64 -S read -S write -S open -S fstat -S mmap -S 
brk -S munmap -S nanosleep -S fcntl -S close -S dup2 -S rt_sigaction -S 
stat
-a exclude,never -F msgtype=NETFILTER_CFG

# The following rule would cause the capture of all systems not caught 
above.
# -a exit,always -S all

# Increase the buffers to survive stress events
-b 8192

# lock the audit configuration to prevent any modification of this file.
-e 2




i installed audit 2.2.2-r2 on gentoo if this is of intzerest.


thank you

marko





-- 
zbfmail - Mittendrin statt nur Datei!

             reply	other threads:[~2014-10-01  6:46 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-10-01  6:46 Marko Weber | 8000 [this message]
2014-10-01 13:55 ` suppress log entries, how? Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=83161eeb858a1d542226038851db7789@zbfmail.de \
    --to=weber@zbfmail.de \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox