12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Analyzing the Records 519the results shown match both requests. To retrieve results that match the search criteria ofone option or another option, perform two different searches and combine the resultsyourself.TABLE 25.3 ausearch OptionsOptionDescription-a Show messages with a specific event ID. Each messagecontains an identification string such as msg=audit(1145758414.468:8758). The number after the colon, suchas 8758 in this example, is the audit event ID. All events froman application’s system call have the same audit event ID sothey can be grouped together.-c Show messages with a specific comm name, which is theexecutable’s name from the task structure. The comm namesuch as firefox-bin or vim is shown when searching for aspecific audit event ID.-f Show messages concerning a specific filename. Useful ifwatching a file with auditctl.-ga Show messages with either an effective group ID or group IDthat matches the given GID.-ge Show messages with an effective group ID that matches thegiven GID.-gi Show messages with a group ID that matches the given GID.-h Display brief help.-hn Show messages containing a specific hostname.-i Show results in human-readable format.-if Read logs from instead of /var/log/audit/audit.log or file set with the log_file parameter in/etc/audit/auditd.conf.log.-k Show messages with .-m Show messages containing a specific message type such asCONFIG_CHANGE or USER_ACCT.-o Show messages containing SE<strong>Linux</strong> tcontext (object)that match the provided string.-p Show messages with a specific process ID.-sc Show messages about a particular system call, specified bythe system call name or its numeric value.-se Show messages containing SE<strong>Linux</strong> scontext/subject ortcontext/object that match the provided string.-su Show messages containing SE<strong>Linux</strong> scontext (subject)that match the provided string.-sv Show successful or failed events by specifying the value yesor no to this option. As shown in Listing 25.8, the successvalue is followed by the res keyword at the end of themessage and can be either success or failed.25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!