12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Tracing a Process with Audit 521LISTING 25.8Continuedtype=USER_END msg=audit(1145210930.022:2025): user pid=30718 uid=0auid=4294967295 msg=’PAM: session close acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/3 res=success)’----time->Fri Dec 1 05:01:01 2006type=CRED_ACQ msg=audit(1145249595.972:2482): user pid=2062 uid=0auid=4294967295 msg=’PAM: setcred acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/6 res=success)’----time->Fri Dec 1 06:01:01 2006type=USER_START msg=audit(1145249595.972:2483): user pid=2062 uid=0auid=4294967295 msg=’PAM: session open acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/6 res=success)’----time->Fri Dec 1 09:01:01 2006type=USER_END msg=audit(1145249595.972:2484): user pid=2062 uid=0auid=4294967295 msg=’PAM: session close acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/6 res=success)’25Tracing a Process with AuditThe autrace utility can be used to generate audit records from a specific process. No otherrules or watches can be enabled while autrace is running. As with the other audit utilities,autrace must be run as root. To audit trace a process, use the following steps:1. Temporarily turn off all rules and watches:auditctl -D2. (Optional) To isolate the audit records from the process, force a log file rotation:service auditd rotateThe logs for the autrace will be in /var/log/audit/audit.log.3. Execute autrace on the command:autrace 4. Wait until the process is complete. A message similar to the following will bedisplayed:Trace complete. You can locate the records with ‘ausearch -i -p 10773’5. Restart the audit daemon to re-enable the rules and watches:service auditd restart6. Use ausearch to display details about the trace.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!