LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 11-22-2016, 05:07 AM   #1
relikwie
LQ Newbie
 
Registered: Sep 2009
Posts: 5

Rep: Reputation: 0
auditd - I have no rules set, still there is activity in audit.log


Hi, I am trying to audit file deletions in a folder, and have set the rule accordignly, but saw a lot of entries being logged of types: USER_ACCTR, CRED_ACQ and USER_AUTH.

I have no idea were these come from, even starting auditd without any rules active, these entries are being logged.

Does anyone have an idea?

thanks much.
 
Old 11-22-2016, 05:48 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by relikwie View Post
I have no idea were these come from, even starting auditd without any rules active, these entries are being logged.
That's because USER_.* and CRED_.* are not related to syscalls or audit itself to generated by user land processes like login?
 
Old 11-23-2016, 04:45 AM   #3
relikwie
LQ Newbie
 
Registered: Sep 2009
Posts: 5

Original Poster
Rep: Reputation: 0
Hi unSpawn, I get what you say. I am on RHEL server, so this means the package "audit" is an addition that adds more audting options.
The issue for me is, that these USER* and CRED* lines are clogging up audit.log. Guess there is no way around it?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
auditctl -l not showing any rules even though i have rules written in audit.rules alphaguy Linux - Security 1 02-07-2014 05:28 PM
The auditd daemon stops logging after deleting audit.log until auditd is restarted Latitude Linux - Security 2 06-20-2013 03:10 PM
pam_tally2 and auditd - failed logins do not make it to audit.log aj33 Linux - Security 7 11-15-2012 01:42 PM
error in line 5 of /etc/audit/audit.rules RHEL5u3 abti Red Hat 1 04-06-2010 05:42 PM
auditd audit.log not display date or user mccartjd Linux - Security 10 06-11-2008 08:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 08:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration