Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Database Support
@ 2008-01-18 11:50 Mukul Khullar
  0 siblings, 0 replies; only message in thread
From: Mukul Khullar @ 2008-01-18 11:50 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1310 bytes --]

I am trying to add DB support to Audit. What kind of DB support is expected
& would be most useful. Should it be on the basis of
1.) Ranges of netlink messages , ie.

* * 000 - 1099 are for commanding the audit system*
* * 1100 - 1199 user space trusted application messages*
* * 1200 - 1299 messages internal to the audit daemon*
 <http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L34>*
* 1300 - 1399 audit event messages*
* * 1400 - 1499 SE Linux use*
 <http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L36>*
* 1500 - 1599 kernel LSPP events*
 <http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L37>*
* 1600 - 1699 kernel crypto events*
 <http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L38>*
* 1700 - 1799 kernel anomaly records*
 <http://www.gelato.unsw.edu.au/lxr/source/include/linux/audit.h#L39>*
* 1800 - 1999 future kernel use (maybe integrity labels and related
events)*


nd etc , or
2.) The tables should be based on each type of record coming in the
logs(which would be a daunting task).
Is there any other way i can use the audit logs, and do some classification
of the records in an efficient manner in the database as tables? What should
be the classification factor for the tables in the DB?

Please reply ,
Thanking You,
Mukul Khullar.

[-- Attachment #1.2: Type: text/html, Size: 1609 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2008-01-18 11:50 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-01-18 11:50 Database Support Mukul Khullar

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox