12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

512CHAPTER 25<strong>Linux</strong> Auditing SystemmsgtypeMessage type number. Should only be used on the exclude filter list.persOS Personality Number.archdevmajordevminorinodeexitsuccessa0, a1, a2, a3keyobj_userobj_roleobj_typeProcessor architecture of the system call. Specify the exact architecturesuch as i686 (can be retrieved from the uname -m command) or b32 touse the 32-bit system call table or b64 to use the 64-bit system call table.Device Major Number.Device Minor Number.Inode Number.Exit value from system call.Success value of system call. Use 1 for true/yes and 0 for false/no.First four arguments to the system call, respectively. Only numericalvalues can be used.Set a filter key with which to tag audit log message for the event. SeeListing 25.2 and Listing 25.3 for examples. Similar to the -k option usedwhen adding watches. Refer to “Writing Audit Rules and Watches” fordetails about the -k option.SE<strong>Linux</strong> user for the resource.SE<strong>Linux</strong> role for the resource.SE<strong>Linux</strong> type for the resource.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!