12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

510CHAPTER 25<strong>Linux</strong> Auditing SystemWriting Audit RulesTo add an audit rule, use the following syntax in the /etc/audit/audit.rules file:-a , CAUTIONIf you add rules /etc/audit/audit.rules while the daemon is running, be sure toenable the changes with the service auditd restart command as root. Theservice auditd reload command can also be used, but you will not be notified ofconfiguration file errors.The list name must be one of the following:taskentryexituserexcludePer task list. It is only used when a task is created. Only fields known at creationtime such as UID can be used with this list.System call entry list. Used when entering a system call to determine if an auditeven should be created.System call exit list. Used when exiting a system call to determine if an auditeven should be created.User message filter list. The kernel uses this list to filter user space events beforepassing them on to the audit daemon. The only valid fields are uid, auid, gid,and pid.Event type exclusion filter list. Used to filter events the administrator doesn’twant to see. Use the msgtype field to specify message types you don’t want to log.The action must be one of the following:neveralwaysDo not generate audit records.Allocate audit context, always fill it in at system call entry, and always write anaudit record at system call exit.The can include one or more of the following:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!