LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE
User Name
Password
SUSE / openSUSE This Forum is for the discussion of Suse Linux.

Notices


Closed Thread
  Search this Thread
Old 11-23-2015, 12:48 PM   #1
fearturtle03
LQ Newbie
 
Registered: Nov 2015
Posts: 3

Rep: Reputation: Disabled
Audit not logging SuSE 10.1


I am using the nispom.rules and stig.rules at /etc/audit.rules to try and audit my 10.1 system. First question would be these files state to place at /etc/audit/audit.rules (which I think is for SuSE 11 as I have gotten audit to work great on those). Should these same rules work for SuSE 10 as long as I place at /etc/audit.rules? They look the same format.

So far I have tried to edit /etc/sysconfig/auditd key AUDITD_DISABLE_CONTEXTS=YES and changed to NO, added the nispom.rules file to /etc/audit.rules and did a reboot.

auditctl -s returns: "enabled=1 flag=1 pid=3598 rate_limit=0 backlog_limit=64 lost=0 backlog=0"

auditctl -l returns: "no rules. File System watches not supported"

The audit.log only grows right after boot then stops (it appears to be the same config information logged each auditd reboot).

Any ideas on what to try and get these rules either loaded properly or auditing? Again I would assume it is the rule set as auditctl -l claims "no rules", but I am not sure why.


Thank You
 
Old 11-29-2015, 05:24 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Duplicate thread of https://www.linuxquestions.org/quest...-a-4175559665/ closed. Please do not do that again.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Audit not logging SuSE 10.1 fearturtle03 Linux - Security 3 11-29-2015 05:18 PM
audit Logging and scripting arn2025 Linux - Newbie 2 01-13-2014 07:23 AM
Samba audit logging not working as expected catkin Linux - Software 2 05-07-2012 10:49 PM
syslog-ng on FC5 only logging audit weisso5 Linux - Software 1 01-07-2008 01:50 PM
Audit Logging Phaethar Linux - Software 0 11-07-2007 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > SUSE / openSUSE

All times are GMT -5. The time now is 11:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration