LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-24-2012, 03:14 AM   #1
8613133
LQ Newbie
 
Registered: Nov 2011
Posts: 11

Rep: Reputation: Disabled
audit daemon in ubuntu


hi,
i installed auditd and then started that.i am going to know if i do not add any rule in audit.rules, what will be happen?does auditd log every things in default without adding any rule?in fact ,auditd log what? when there is no rule in audit.rules,
thanks.
 
Old 05-24-2012, 03:35 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by 8613133 View Post
does auditd log every things in default without adding any rule?
No.


Quote:
Originally Posted by 8613133 View Post
i am going to know if i do not add any rule in audit.rules, what will be happen?
You are going to know by reading the contents of /var/log/audit/audit.log or wherever you configured the audit service to log to.
 
Old 05-30-2012, 01:56 PM   #3
8613133
LQ Newbie
 
Registered: Nov 2011
Posts: 11

Original Poster
Rep: Reputation: Disabled
hi,
i am logging with auditd . i need to know the mode and flag of each syscall,but audit.log does not show them.is there any way to see those fields?

one other question,
how can i see %mem and %cpu each process(pid) that was logged in audit daemon?(in fact %mem and %cpu of pid which is in the log file)
thanks

Last edited by unSpawn; 06-02-2012 at 07:35 PM.
 
Old 06-02-2012, 08:27 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by 8613133 View Post
i need to know the mode and flag of each syscall
If I audit execve it lists the amount of args and each arg. What do you mean "mode and flag"?


Quote:
Originally Posted by 8613133 View Post
how can i see %mem and %cpu each process(pid) that was logged in audit daemon?(in fact %mem and %cpu of pid which is in the log file)
The audit service has no concept of SAR (system activity reporting) in that sense. You can correlate data if you collect it using a separate tool like Atop, Collectl, Atsar, Dstat or Sar.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
audit daemon zanier Linux - Newbie 6 05-24-2012 08:21 AM
Problem with audit daemon? agostino84 Red Hat 1 12-22-2008 04:44 PM
Configuring the audit daemon of RHEL4 update 2 herrmag Linux - Security 0 05-08-2006 04:39 PM
what's audit daemon for? liyuefu Linux - General 2 06-23-2005 11:37 AM
Audit Daemon in RH 7.3 oulevon Linux - Security 1 08-06-2002 07:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration