From mboxrd@z Thu Jan 1 00:00:00 1970
From: khalid fahad
Subject: Audit log decode
Date: Tue, 11 Sep 2018 21:44:05 +0930
Message-ID:
Mime-Version: 1.0 (1.0)
Content-Type: multipart/mixed; boundary="===============4121559704229265728=="
Return-path:
Received: from mx1.redhat.com (ext-mx19.extmail.prod.ext.phx2.redhat.com
[10.5.110.48])
by smtp.corp.redhat.com (Postfix) with ESMTPS id 8406C6012D
for ; Tue, 11 Sep 2018 12:14:11 +0000 (UTC)
Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com
[209.85.214.169])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by mx1.redhat.com (Postfix) with ESMTPS id 4B90C307D867
for ; Tue, 11 Sep 2018 12:14:10 +0000 (UTC)
Received: by mail-pl1-f169.google.com with SMTP id b12-v6so11243347plr.8
for ; Tue, 11 Sep 2018 05:14:10 -0700 (PDT)
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
Sender: linux-audit-bounces@redhat.com
Errors-To: linux-audit-bounces@redhat.com
To: linux-audit@redhat.com
List-Id: linux-audit@redhat.com
--===============4121559704229265728==
Content-Type: multipart/alternative;
boundary=Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954
Content-Transfer-Encoding: 7bit
--Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954
Content-Type: text/plain;
charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Hi,
I need help to decode the following records in audit.log. Thanks
type=3DPROCTITLE msg=3Daudit(100000000.000:000): proctitle=3D726D002F7661722=
F6C6F672F736563757265=20
type=3DPATH msg=3Daudit(100000000.000:000): item=3D1 name=3D"/var/log/secure=
" inode=3D34679270 dev=3Dfd:00 mode=3D0100600 ouid=3D0 ogid=3D0 rdev=3D00:00=
obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DDELETE=20
type=3DPATH msg=3Daudit(100000000.000:000): item=3D0 name=3D"/var/log/" inod=
e=3D33586091 dev=3Dfd:00 mode=3D040755 ouid=3D0 ogid=3D0 rdev=3D00:00 obj=3D=
system_u:object_r:var_log_t:s0 objtype=3DPARENT
type=3DCWD msg=3Daudit(100000000.000:000): cwd=3D"/home/adminuser"=20
type=3DSYSCALL msg=3Daudit(100000000.000:000): arch=3Dc000003e syscall=3D263=
success=3Dno exit=3D-13 a0=3Dffffffffffffff9c a1=3Db830c0 a2=3D0 a3=3D7ffc9=
bd9d600 items=3D2 ppid=3D3493 pid=3D35055 auid=3D1000 uid=3D1000 gid=3D1000 e=
uid=3D1000 suid=3D1000 fsuid=3D1000 egid=3D1000 sgid=3D1000 fsgid=3D1000 tty=
=3Dpts2 ses=3D1 comm=3D"rm" exe=3D"/usr/bin/rm" subj=3Dunconfined_u:unconfin=
ed_r:unconfined_t:s0-s0:c0.c1023 key=3D"secure_log"
--Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954
Content-Type: text/html;
charset=utf-8
Content-Transfer-Encoding: 7bit
Hi,I need help to decode the following records in audit.log. Thanks
type=PROCTITLE msg=audit(100000000.000:000): proctitle=726D002F7661722F6C6F672F736563757265
type=PATH msg=audit(100000000.000:000): item=1 name="/var/log/secure" inode=34679270 dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=DELETE
type=PATH msg=audit(100000000.000:000): item=0 name="/var/log/" inode=33586091 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=PARENT
type=CWD msg=audit(100000000.000:000): cwd="/home/adminuser"
type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600 items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1 comm="rm" exe="/usr/bin/rm" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="secure_log"
--Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954--
--===============4121559704229265728==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============4121559704229265728==--
From mboxrd@z Thu Jan 1 00:00:00 1970
From: Osama Elnaggar
Subject: Re: Audit log decode
Date: Tue, 11 Sep 2018 08:19:51 -0400
Message-ID:
References:
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="===============1199187027699770478=="
Return-path:
Received: from mx1.redhat.com (ext-mx02.extmail.prod.ext.phx2.redhat.com
[10.5.110.26])
by smtp.corp.redhat.com (Postfix) with ESMTPS id B4BAC1062244
for ; Tue, 11 Sep 2018 12:19:54 +0000 (UTC)
Received: from mail-qt0-f178.google.com (mail-qt0-f178.google.com
[209.85.216.178])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by mx1.redhat.com (Postfix) with ESMTPS id C14C587644
for ; Tue, 11 Sep 2018 12:19:52 +0000 (UTC)
Received: by mail-qt0-f178.google.com with SMTP id o15-v6so27889199qtk.6
for ; Tue, 11 Sep 2018 05:19:52 -0700 (PDT)
In-Reply-To:
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
Sender: linux-audit-bounces@redhat.com
Errors-To: linux-audit-bounces@redhat.com
To: khalid fahad , linux-audit@redhat.com
List-Id: linux-audit@redhat.com
--===============1199187027699770478==
Content-Type: multipart/alternative; boundary="000000000000a5034d0575977d70"
--000000000000a5034d0575977d70
Content-Type: text/plain; charset="UTF-8"
Just save it to a file and use ausearch -i to do the interpolation for
you. For example:
ausearch -if /tmp/testentry -i
where /tmp/testentry contains the below entry
Run it on the same system it was generated on so the UID and other lookups
are accurate
--
Osama Elnaggar
On September 11, 2018 at 10:14:27 PM, khalid fahad (kfgm2001@gmail.com)
wrote:
Hi,
I need help to decode the following records in audit.log. Thanks
type=PROCTITLE msg=audit(100000000.000:000):
proctitle=726D002F7661722F6C6F672F736563757265
type=PATH msg=audit(100000000.000:000): item=1 name="/var/log/secure"
inode=34679270 dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00
obj=system_u:object_r:var_log_t:s0 objtype=DELETE
type=PATH msg=audit(100000000.000:000): item=0 name="/var/log/"
inode=33586091 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00
obj=system_u:object_r:var_log_t:s0 objtype=PARENT
type=CWD msg=audit(100000000.000:000): cwd="/home/adminuser"
type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263
success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600
items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000
fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1 comm="rm"
exe="/usr/bin/rm"
subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="secure_log"
--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit
--000000000000a5034d0575977d70
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
=
Just save it to a fi=
le and use ausearch -i to do the interpolation for you.=C2=A0 For example:<=
/div>
ausearch -if /tmp/tes=
tentry -i
where /tmp/testentry contains the below=
entry
Run it on the same system it was generated =
on so the UID and other lookups are accurate
<=
p class=3D"airmail_on">On September 11, 2018 at 10:14:27 PM, khalid fahad (=
kfgm2001@gmail.com) wrote:
Hi,
I need help to decode the following records in audit.log.
Thanks
type=3DPROCTITLE
msg=3Daudit(100000000.000:000):
proctitle=3D726D002F7661722F6C6F672F736563757265=C2=A0
type=3DPATH
msg=3Daudit(100000000.000:000): item=3D1 name=3D"/var/log/secure"
inode=3D34679270 dev=3Dfd:00 mode=3D0100600 ouid=3D0 ogid=3D0 rdev=3D00:00
obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DDELETE=C2=A0
type=3DPATH
msg=3Daudit(100000000.000:000): item=3D0 name=3D"/var/log/"
inode=3D33586091 dev=3Dfd:00 mode=3D040755 ouid=3D0 ogid=3D0 rdev=3D00:00
obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DPARENT
type=3DCWD
msg=3Daudit(100000000.000:000):=C2=A0
cwd=3D"/home/adminuser"=C2=A0
type=3DSYSCALL
msg=3Daudit(100000000.000:000): arch=3Dc000003e syscall=3D263 success=3Dno
exit=3D-13 a0=3Dffffffffffffff9c a1=3Db830c0 a2=3D0 a3=3D7ffc9bd9d600 items=
=3D2
ppid=3D3493 pid=3D35055 auid=3D1000 uid=3D1000 gid=3D1000 euid=3D1000 suid=
=3D1000
fsuid=3D1000 egid=3D1000 sgid=3D1000 fsgid=3D1000 tty=3Dpts2 ses=3D1 comm=
=3D"rm"
exe=3D"/usr/bin/rm"
subj=3Dunconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
key=3D"secure_log"
--
Linux-audit mailing list
Linux-audit@redhat.com
https:/=
/www.redhat.com/mailman/listinfo/linux-audit
--000000000000a5034d0575977d70--
--===============1199187027699770478==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============1199187027699770478==--
From mboxrd@z Thu Jan 1 00:00:00 1970
From: Steve Grubb
Subject: Re: Audit log decode
Date: Tue, 11 Sep 2018 08:21:44 -0400
Message-ID: <8355452.a5mgvV1NuZ@x2>
References:
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Return-path:
In-Reply-To:
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
Sender: linux-audit-bounces@redhat.com
Errors-To: linux-audit-bounces@redhat.com
To: linux-audit@redhat.com
List-Id: linux-audit@redhat.com
On Tuesday, September 11, 2018 8:14:05 AM EDT khalid fahad wrote:
> Hi,
> I need help to decode the following records in audit.log. Thanks
> type=PROCTITLE msg=audit(100000000.000:000):
> proctitle=726D002F7661722F6C6F672F736563757265 type=PATH
> msg=audit(100000000.000:000): item=1 name="/var/log/secure" inode=34679270
> dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00
> obj=system_u:object_r:var_log_t:s0 objtype=DELETE type=PATH
> msg=audit(100000000.000:000): item=0 name="/var/log/" inode=33586091
> dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00
> obj=system_u:object_r:var_log_t:s0 objtype=PARENT type=CWD
> msg=audit(100000000.000:000): cwd="/home/adminuser"
> type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263
> success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600
> items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000
> suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1
> comm="rm" exe="/usr/bin/rm"
> subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
> key="secure_log"
The ausearch program is able to decode this and is meant to display the audit
loags. If you have that in a file named log, you can just do something like
ausearch -if log -i
and that should decode your event.
-Steve
From mboxrd@z Thu Jan 1 00:00:00 1970
From: khalid fahad
Subject: Re: Audit log decode
Date: Tue, 11 Sep 2018 23:35:11 +0930
Message-ID:
References:
<8355452.a5mgvV1NuZ@x2>
Mime-Version: 1.0 (1.0)
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
Return-path:
In-Reply-To: <8355452.a5mgvV1NuZ@x2>
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
Sender: linux-audit-bounces@redhat.com
Errors-To: linux-audit-bounces@redhat.com
To: Steve Grubb
Cc: linux-audit@redhat.com
List-Id: linux-audit@redhat.com
SXQgd2FzbuKAmXQgd29yayB3aXRoIG1lLiBJIGhhdmUgYW4gaXNzdWUuCgpTZW50IGZyb20gbXkg
aVBob25lCgo+IE9uIDExIFNlcCAyMDE4LCBhdCA5OjUxIHBtLCBTdGV2ZSBHcnViYiA8c2dydWJi
QHJlZGhhdC5jb20+IHdyb3RlOgo+IAo+PiBPbiBUdWVzZGF5LCBTZXB0ZW1iZXIgMTEsIDIwMTgg
ODoxNDowNSBBTSBFRFQga2hhbGlkIGZhaGFkIHdyb3RlOgo+PiBIaSwKPj4gSSBuZWVkIGhlbHAg
dG8gZGVjb2RlIHRoZSBmb2xsb3dpbmcgcmVjb3JkcyBpbiBhdWRpdC5sb2cuIFRoYW5rcwo+PiB0
eXBlPVBST0NUSVRMRSBtc2c9YXVkaXQoMTAwMDAwMDAwLjAwMDowMDApOgo+PiBwcm9jdGl0bGU9
NzI2RDAwMkY3NjYxNzIyRjZDNkY2NzJGNzM2NTYzNzU3MjY1IHR5cGU9UEFUSAo+PiBtc2c9YXVk
aXQoMTAwMDAwMDAwLjAwMDowMDApOiBpdGVtPTEgbmFtZT0iL3Zhci9sb2cvc2VjdXJlIiBpbm9k
ZT0zNDY3OTI3MAo+PiBkZXY9ZmQ6MDAgbW9kZT0wMTAwNjAwIG91aWQ9MCBvZ2lkPTAgcmRldj0w
MDowMAo+PiBvYmo9c3lzdGVtX3U6b2JqZWN0X3I6dmFyX2xvZ190OnMwIG9ianR5cGU9REVMRVRF
IHR5cGU9UEFUSAo+PiBtc2c9YXVkaXQoMTAwMDAwMDAwLjAwMDowMDApOiBpdGVtPTAgbmFtZT0i
L3Zhci9sb2cvIiBpbm9kZT0zMzU4NjA5MQo+PiBkZXY9ZmQ6MDAgbW9kZT0wNDA3NTUgb3VpZD0w
IG9naWQ9MCByZGV2PTAwOjAwCj4+IG9iaj1zeXN0ZW1fdTpvYmplY3Rfcjp2YXJfbG9nX3Q6czAg
b2JqdHlwZT1QQVJFTlQgdHlwZT1DV0QKPj4gbXNnPWF1ZGl0KDEwMDAwMDAwMC4wMDA6MDAwKTog
IGN3ZD0iL2hvbWUvYWRtaW51c2VyIgo+PiB0eXBlPVNZU0NBTEwgbXNnPWF1ZGl0KDEwMDAwMDAw
MC4wMDA6MDAwKTogYXJjaD1jMDAwMDAzZSBzeXNjYWxsPTI2Mwo+PiBzdWNjZXNzPW5vIGV4aXQ9
LTEzIGEwPWZmZmZmZmZmZmZmZmZmOWMgYTE9YjgzMGMwIGEyPTAgYTM9N2ZmYzliZDlkNjAwCj4+
IGl0ZW1zPTIgcHBpZD0zNDkzIHBpZD0zNTA1NSBhdWlkPTEwMDAgdWlkPTEwMDAgZ2lkPTEwMDAg
ZXVpZD0xMDAwCj4+IHN1aWQ9MTAwMCBmc3VpZD0xMDAwIGVnaWQ9MTAwMCBzZ2lkPTEwMDAgZnNn
aWQ9MTAwMCB0dHk9cHRzMiBzZXM9MQo+PiBjb21tPSJybSIgZXhlPSIvdXNyL2Jpbi9ybSIKPj4g
c3Viaj11bmNvbmZpbmVkX3U6dW5jb25maW5lZF9yOnVuY29uZmluZWRfdDpzMC1zMDpjMC5jMTAy
Mwo+PiBrZXk9InNlY3VyZV9sb2ciCj4gCj4gVGhlIGF1c2VhcmNoIHByb2dyYW0gaXMgYWJsZSB0
byBkZWNvZGUgdGhpcyBhbmQgaXMgbWVhbnQgdG8gZGlzcGxheSB0aGUgYXVkaXQgCj4gbG9hZ3Mu
IElmIHlvdSBoYXZlIHRoYXQgaW4gYSBmaWxlIG5hbWVkIGxvZywgeW91IGNhbiBqdXN0IGRvIHNv
bWV0aGluZyBsaWtlIAo+IAo+IGF1c2VhcmNoIC1pZiBsb2cgLWkKPiAKPiBhbmQgdGhhdCBzaG91
bGQgZGVjb2RlIHlvdXIgZXZlbnQuCj4gCj4gLVN0ZXZlCj4gCj4gCgotLQpMaW51eC1hdWRpdCBt
YWlsaW5nIGxpc3QKTGludXgtYXVkaXRAcmVkaGF0LmNvbQpodHRwczovL3d3dy5yZWRoYXQuY29t
L21haWxtYW4vbGlzdGluZm8vbGludXgtYXVkaXQ=