11.07.2015 Views

audit

audit

audit

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PROCESSING : MESSAGE GROUPSA few more fun examples of grouping./var/resolvconf/interface$ cat eth0.dhclient nginx: int fd = open(“/www/index.html”); // fd == 13 fd = accept(“192.168.56.1:51997”); user “mthomas” started a pam session[]{"exe": "/bin/cat","comm": "cat","ses": 10,"auid": 4294967295,"pid": 31335,"ppid": 31334,"items": 2,"exit": 0,"success": "yes","syscall": "execve","epoch": 1399248110,"serial": 855516,"type": "SYSCALL"},{"a1": "eth0.dhclient","a0": "cat","argc": 2,"epoch": 1399248110,"type": "EXECVE"},{"cwd": "/run/resolvconf/interface","epoch": 1399248110,"type": "CWD"},{"name": "/bin/cat","epoch": 1399248110,"type": "PATH"}[]{"exe": "/usr/sbin/nginx","comm": "nginx","ses": 238,"pid": 966,"ppid": 965,"items": 1,"a3": "fffffffffffffffb","a2": 0,"a1": "800","a0": "ee7c05","exit": 13,"success": "yes","syscall": "open","epoch": 1392316421,"serial": 301316,"type": "SYSCALL"},{"cwd": "/","type": "CWD"},{"ogid": 0,"name": "/www/index.html","type": "PATH"}[]{"exe": "/usr/sbin/nginx","comm": "nginx","ses": 238,"pid": 966,"ppid": 965,"items": 0,"a3": "800","a2": "7fff8afba6cc","a1": "7fff8afba6d0","a0": 0,"exit": 12,"success": "yes","syscall": "accept4","epoch": 1392316421,"serial": 301314,"type": "SYSCALL"},{"saddr": "192.168.56.1","port": 51997,"prot": "ipv4","type": "SOCKADDR"}[]{}"res": "success","terminal": "ssh","addr": "192.168.56.1","hostname": "babby.local","exe": "/usr/sbin/sshd","acct": "mthomas","op": "PAM:session_open","ses": 24,"auid": 1000,"uid": 0,"pid": 10469,"epoch": 1393886985,"serial": 3393,"type": "USER_START"

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!