From: "Mukul Khullar" <auditmk@gmail.com>
To: linux-audit@redhat.com
Subject: Database Support
Date: Fri, 18 Jan 2008 17:20:35 +0530 [thread overview]
Message-ID: <b484796a0801180350i69e3ad2ch4fea3b4b101132ae@mail.gmail.com> (raw)
[-- Attachment #1.1: Type: text/plain, Size: 1310 bytes --]
I am trying to add DB support to Audit. What kind of DB support is expected
& would be most useful. Should it be on the basis of
1.) Ranges of netlink messages , ie.
* * 000 - 1099 are for commanding the audit system*
* * 1100 - 1199 user space trusted application messages*
* * 1200 - 1299 messages internal to the audit daemon*
<http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L34>*
* 1300 - 1399 audit event messages*
* * 1400 - 1499 SE Linux use*
<http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L36>*
* 1500 - 1599 kernel LSPP events*
<http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L37>*
* 1600 - 1699 kernel crypto events*
<http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L38>*
* 1700 - 1799 kernel anomaly records*
<http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L39>*
* 1800 - 1999 future kernel use (maybe integrity labels and related
events)*
nd etc , or
2.) The tables should be based on each type of record coming in the
logs(which would be a daunting task).
Is there any other way i can use the audit logs, and do some classification
of the records in an efficient manner in the database as tables? What should
be the classification factor for the tables in the DB?
Please reply ,
Thanking You,
Mukul Khullar.
[-- Attachment #1.2: Type: text/html, Size: 1609 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
reply other threads:[~2008-01-18 11:50 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b484796a0801180350i69e3ad2ch4fea3b4b101132ae@mail.gmail.com \
--to=auditmk@gmail.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox