LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 03-21-2013, 05:51 AM   #1
kanishka.dutta
LQ Newbie
 
Registered: Dec 2012
Posts: 11

Rep: Reputation: Disabled
Linux kernel Audit support


I have enabled the Linux kernel audit support and am able to get the audit.log file properly.

But I need to check for a particular scenario where my Linux machine goes to deep sleep and then wakes up from that state. I need to collect the logs during this transition. Meaning to say - I would like to audit which files/processes is getting audited during this transition (wake up from deep sleep).

Please let me know what else I should do along with enabling the Linux kernel audit support?
 
Old 03-22-2013, 02:52 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by kanishka.dutta View Post
(..) I would like to audit which files/processes is getting audited during this transition (wake up from deep sleep).
Which files and processes are getting audited depends on your audit.rules contents and if those rules are loaded. Your problem is that while the audit service doesn't run messages (should) get pushed to syslog instead of audit.log and additionally that until the Syslog service runs it won't store messages anyway. Increasing the message buffer may help to some extent.
 
1 members found this post helpful.
Old 04-10-2013, 04:57 AM   #3
kanishka.dutta
LQ Newbie
 
Registered: Dec 2012
Posts: 11

Original Poster
Rep: Reputation: Disabled
Thanks for the response.

I am able to get the audit.log(s) files now. I would like to know, why is there no daemon process entries in the log file? Is there any specific settings/configurations that we need to do, in order to track the daemon processes as well?

Please guide ...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Kernel Audit Support Unavaible error when booting after kernel upgrade abefroman Red Hat 2 03-21-2013 08:32 AM
Can Red hat Linux 9 support Audit? nnnnnng Red Hat 7 02-08-2012 01:35 PM
How can I read the audit time stamp? msg=audit(1213186256.105:20663) abefroman Linux - Software 3 04-21-2011 06:37 PM
[Linux Audit]: Which groups should be allowed to read audit log files? quanba Linux - Security 1 11-15-2010 10:09 AM
error in line 5 of /etc/audit/audit.rules RHEL5u3 abti Red Hat 1 04-06-2010 05:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 02:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration