From mboxrd@z Thu Jan 1 00:00:00 1970 From: khalid fahad Subject: Audit log decode Date: Tue, 11 Sep 2018 21:44:05 +0930 Message-ID: Mime-Version: 1.0 (1.0) Content-Type: multipart/mixed; boundary="===============4121559704229265728==" Return-path: Received: from mx1.redhat.com (ext-mx19.extmail.prod.ext.phx2.redhat.com [10.5.110.48]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 8406C6012D for ; Tue, 11 Sep 2018 12:14:11 +0000 (UTC) Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 4B90C307D867 for ; Tue, 11 Sep 2018 12:14:10 +0000 (UTC) Received: by mail-pl1-f169.google.com with SMTP id b12-v6so11243347plr.8 for ; Tue, 11 Sep 2018 05:14:10 -0700 (PDT) List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============4121559704229265728== Content-Type: multipart/alternative; boundary=Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954 Content-Transfer-Encoding: 7bit --Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable Hi, I need help to decode the following records in audit.log. Thanks type=3DPROCTITLE msg=3Daudit(100000000.000:000): proctitle=3D726D002F7661722= F6C6F672F736563757265=20 type=3DPATH msg=3Daudit(100000000.000:000): item=3D1 name=3D"/var/log/secure= " inode=3D34679270 dev=3Dfd:00 mode=3D0100600 ouid=3D0 ogid=3D0 rdev=3D00:00= obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DDELETE=20 type=3DPATH msg=3Daudit(100000000.000:000): item=3D0 name=3D"/var/log/" inod= e=3D33586091 dev=3Dfd:00 mode=3D040755 ouid=3D0 ogid=3D0 rdev=3D00:00 obj=3D= system_u:object_r:var_log_t:s0 objtype=3DPARENT type=3DCWD msg=3Daudit(100000000.000:000): cwd=3D"/home/adminuser"=20 type=3DSYSCALL msg=3Daudit(100000000.000:000): arch=3Dc000003e syscall=3D263= success=3Dno exit=3D-13 a0=3Dffffffffffffff9c a1=3Db830c0 a2=3D0 a3=3D7ffc9= bd9d600 items=3D2 ppid=3D3493 pid=3D35055 auid=3D1000 uid=3D1000 gid=3D1000 e= uid=3D1000 suid=3D1000 fsuid=3D1000 egid=3D1000 sgid=3D1000 fsgid=3D1000 tty= =3Dpts2 ses=3D1 comm=3D"rm" exe=3D"/usr/bin/rm" subj=3Dunconfined_u:unconfin= ed_r:unconfined_t:s0-s0:c0.c1023 key=3D"secure_log" --Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit Hi,
I need help to decode the following records in audit.log. Thanks

type=PROCTITLE msg=audit(100000000.000:000): proctitle=726D002F7661722F6C6F672F736563757265 

type=PATH msg=audit(100000000.000:000): item=1 name="/var/log/secure" inode=34679270 dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=DELETE 

type=PATH msg=audit(100000000.000:000): item=0 name="/var/log/" inode=33586091 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=PARENT

type=CWD msg=audit(100000000.000:000):  cwd="/home/adminuser" 

type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600 items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1 comm="rm" exe="/usr/bin/rm" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="secure_log"


--Apple-Mail-476CA57A-D86E-49A2-A965-117D966DB954-- --===============4121559704229265728== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============4121559704229265728==-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Osama Elnaggar Subject: Re: Audit log decode Date: Tue, 11 Sep 2018 08:19:51 -0400 Message-ID: References: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1199187027699770478==" Return-path: Received: from mx1.redhat.com (ext-mx02.extmail.prod.ext.phx2.redhat.com [10.5.110.26]) by smtp.corp.redhat.com (Postfix) with ESMTPS id B4BAC1062244 for ; Tue, 11 Sep 2018 12:19:54 +0000 (UTC) Received: from mail-qt0-f178.google.com (mail-qt0-f178.google.com [209.85.216.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id C14C587644 for ; Tue, 11 Sep 2018 12:19:52 +0000 (UTC) Received: by mail-qt0-f178.google.com with SMTP id o15-v6so27889199qtk.6 for ; Tue, 11 Sep 2018 05:19:52 -0700 (PDT) In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: khalid fahad , linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============1199187027699770478== Content-Type: multipart/alternative; boundary="000000000000a5034d0575977d70" --000000000000a5034d0575977d70 Content-Type: text/plain; charset="UTF-8" Just save it to a file and use ausearch -i to do the interpolation for you. For example: ausearch -if /tmp/testentry -i where /tmp/testentry contains the below entry Run it on the same system it was generated on so the UID and other lookups are accurate -- Osama Elnaggar On September 11, 2018 at 10:14:27 PM, khalid fahad (kfgm2001@gmail.com) wrote: Hi, I need help to decode the following records in audit.log. Thanks type=PROCTITLE msg=audit(100000000.000:000): proctitle=726D002F7661722F6C6F672F736563757265 type=PATH msg=audit(100000000.000:000): item=1 name="/var/log/secure" inode=34679270 dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=DELETE type=PATH msg=audit(100000000.000:000): item=0 name="/var/log/" inode=33586091 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_log_t:s0 objtype=PARENT type=CWD msg=audit(100000000.000:000): cwd="/home/adminuser" type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600 items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1 comm="rm" exe="/usr/bin/rm" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="secure_log" -- Linux-audit mailing list Linux-audit@redhat.com https://www.redhat.com/mailman/listinfo/linux-audit --000000000000a5034d0575977d70 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable = Just save it to a fi= le and use ausearch -i to do the interpolation for you.=C2=A0 For example:<= /div>

ausearch -if /tmp/tes= tentry -i

where /tmp/testentry contains the below= entry

Run it on the same system it was generated = on so the UID and other lookups are accurate

--=C2=A0
Osama Elnaggar

<= p class=3D"airmail_on">On September 11, 2018 at 10:14:27 PM, khalid fahad (= kfgm2001@gmail.com) wrote:

Hi,
I need help to decode the following records in audit.log. Thanks

type=3DPROCTITLE msg=3Daudit(100000000.000:000): proctitle=3D726D002F7661722F6C6F672F736563757265=C2=A0

type=3DPATH msg=3Daudit(100000000.000:000): item=3D1 name=3D"/var/log/secure" inode=3D34679270 dev=3Dfd:00 mode=3D0100600 ouid=3D0 ogid=3D0 rdev=3D00:00 obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DDELETE=C2=A0

type=3DPATH msg=3Daudit(100000000.000:000): item=3D0 name=3D"/var/log/" inode=3D33586091 dev=3Dfd:00 mode=3D040755 ouid=3D0 ogid=3D0 rdev=3D00:00 obj=3Dsystem_u:object_r:var_log_t:s0 objtype=3DPARENT

type=3DCWD msg=3Daudit(100000000.000:000):=C2=A0 cwd=3D"/home/adminuser"=C2=A0

type=3DSYSCALL msg=3Daudit(100000000.000:000): arch=3Dc000003e syscall=3D263 success=3Dno exit=3D-13 a0=3Dffffffffffffff9c a1=3Db830c0 a2=3D0 a3=3D7ffc9bd9d600 items= =3D2 ppid=3D3493 pid=3D35055 auid=3D1000 uid=3D1000 gid=3D1000 euid=3D1000 suid= =3D1000 fsuid=3D1000 egid=3D1000 sgid=3D1000 fsgid=3D1000 tty=3Dpts2 ses=3D1 comm= =3D"rm" exe=3D"/usr/bin/rm" subj=3Dunconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=3D"secure_log"


--
Linux-audit mailing list
Linux-audit@redhat.com
https:/= /www.redhat.com/mailman/listinfo/linux-audit
--000000000000a5034d0575977d70-- --===============1199187027699770478== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1199187027699770478==-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Audit log decode Date: Tue, 11 Sep 2018 08:21:44 -0400 Message-ID: <8355452.a5mgvV1NuZ@x2> References: Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Tuesday, September 11, 2018 8:14:05 AM EDT khalid fahad wrote: > Hi, > I need help to decode the following records in audit.log. Thanks > type=PROCTITLE msg=audit(100000000.000:000): > proctitle=726D002F7661722F6C6F672F736563757265 type=PATH > msg=audit(100000000.000:000): item=1 name="/var/log/secure" inode=34679270 > dev=fd:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 > obj=system_u:object_r:var_log_t:s0 objtype=DELETE type=PATH > msg=audit(100000000.000:000): item=0 name="/var/log/" inode=33586091 > dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 > obj=system_u:object_r:var_log_t:s0 objtype=PARENT type=CWD > msg=audit(100000000.000:000): cwd="/home/adminuser" > type=SYSCALL msg=audit(100000000.000:000): arch=c000003e syscall=263 > success=no exit=-13 a0=ffffffffffffff9c a1=b830c0 a2=0 a3=7ffc9bd9d600 > items=2 ppid=3493 pid=35055 auid=1000 uid=1000 gid=1000 euid=1000 > suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 tty=pts2 ses=1 > comm="rm" exe="/usr/bin/rm" > subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 > key="secure_log" The ausearch program is able to decode this and is meant to display the audit loags. If you have that in a file named log, you can just do something like ausearch -if log -i and that should decode your event. -Steve From mboxrd@z Thu Jan 1 00:00:00 1970 From: khalid fahad Subject: Re: Audit log decode Date: Tue, 11 Sep 2018 23:35:11 +0930 Message-ID: References: <8355452.a5mgvV1NuZ@x2> Mime-Version: 1.0 (1.0) Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: In-Reply-To: <8355452.a5mgvV1NuZ@x2> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com SXQgd2FzbuKAmXQgd29yayB3aXRoIG1lLiBJIGhhdmUgYW4gaXNzdWUuCgpTZW50IGZyb20gbXkg aVBob25lCgo+IE9uIDExIFNlcCAyMDE4LCBhdCA5OjUxIHBtLCBTdGV2ZSBHcnViYiA8c2dydWJi QHJlZGhhdC5jb20+IHdyb3RlOgo+IAo+PiBPbiBUdWVzZGF5LCBTZXB0ZW1iZXIgMTEsIDIwMTgg ODoxNDowNSBBTSBFRFQga2hhbGlkIGZhaGFkIHdyb3RlOgo+PiBIaSwKPj4gSSBuZWVkIGhlbHAg dG8gZGVjb2RlIHRoZSBmb2xsb3dpbmcgcmVjb3JkcyBpbiBhdWRpdC5sb2cuIFRoYW5rcwo+PiB0 eXBlPVBST0NUSVRMRSBtc2c9YXVkaXQoMTAwMDAwMDAwLjAwMDowMDApOgo+PiBwcm9jdGl0bGU9 NzI2RDAwMkY3NjYxNzIyRjZDNkY2NzJGNzM2NTYzNzU3MjY1IHR5cGU9UEFUSAo+PiBtc2c9YXVk aXQoMTAwMDAwMDAwLjAwMDowMDApOiBpdGVtPTEgbmFtZT0iL3Zhci9sb2cvc2VjdXJlIiBpbm9k ZT0zNDY3OTI3MAo+PiBkZXY9ZmQ6MDAgbW9kZT0wMTAwNjAwIG91aWQ9MCBvZ2lkPTAgcmRldj0w MDowMAo+PiBvYmo9c3lzdGVtX3U6b2JqZWN0X3I6dmFyX2xvZ190OnMwIG9ianR5cGU9REVMRVRF IHR5cGU9UEFUSAo+PiBtc2c9YXVkaXQoMTAwMDAwMDAwLjAwMDowMDApOiBpdGVtPTAgbmFtZT0i L3Zhci9sb2cvIiBpbm9kZT0zMzU4NjA5MQo+PiBkZXY9ZmQ6MDAgbW9kZT0wNDA3NTUgb3VpZD0w IG9naWQ9MCByZGV2PTAwOjAwCj4+IG9iaj1zeXN0ZW1fdTpvYmplY3Rfcjp2YXJfbG9nX3Q6czAg b2JqdHlwZT1QQVJFTlQgdHlwZT1DV0QKPj4gbXNnPWF1ZGl0KDEwMDAwMDAwMC4wMDA6MDAwKTog IGN3ZD0iL2hvbWUvYWRtaW51c2VyIgo+PiB0eXBlPVNZU0NBTEwgbXNnPWF1ZGl0KDEwMDAwMDAw MC4wMDA6MDAwKTogYXJjaD1jMDAwMDAzZSBzeXNjYWxsPTI2Mwo+PiBzdWNjZXNzPW5vIGV4aXQ9 LTEzIGEwPWZmZmZmZmZmZmZmZmZmOWMgYTE9YjgzMGMwIGEyPTAgYTM9N2ZmYzliZDlkNjAwCj4+ IGl0ZW1zPTIgcHBpZD0zNDkzIHBpZD0zNTA1NSBhdWlkPTEwMDAgdWlkPTEwMDAgZ2lkPTEwMDAg ZXVpZD0xMDAwCj4+IHN1aWQ9MTAwMCBmc3VpZD0xMDAwIGVnaWQ9MTAwMCBzZ2lkPTEwMDAgZnNn aWQ9MTAwMCB0dHk9cHRzMiBzZXM9MQo+PiBjb21tPSJybSIgZXhlPSIvdXNyL2Jpbi9ybSIKPj4g c3Viaj11bmNvbmZpbmVkX3U6dW5jb25maW5lZF9yOnVuY29uZmluZWRfdDpzMC1zMDpjMC5jMTAy Mwo+PiBrZXk9InNlY3VyZV9sb2ciCj4gCj4gVGhlIGF1c2VhcmNoIHByb2dyYW0gaXMgYWJsZSB0 byBkZWNvZGUgdGhpcyBhbmQgaXMgbWVhbnQgdG8gZGlzcGxheSB0aGUgYXVkaXQgCj4gbG9hZ3Mu IElmIHlvdSBoYXZlIHRoYXQgaW4gYSBmaWxlIG5hbWVkIGxvZywgeW91IGNhbiBqdXN0IGRvIHNv bWV0aGluZyBsaWtlIAo+IAo+IGF1c2VhcmNoIC1pZiBsb2cgLWkKPiAKPiBhbmQgdGhhdCBzaG91 bGQgZGVjb2RlIHlvdXIgZXZlbnQuCj4gCj4gLVN0ZXZlCj4gCj4gCgotLQpMaW51eC1hdWRpdCBt YWlsaW5nIGxpc3QKTGludXgtYXVkaXRAcmVkaGF0LmNvbQpodHRwczovL3d3dy5yZWRoYXQuY29t L21haWxtYW4vbGlzdGluZm8vbGludXgtYXVkaXQ=