LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-11-2016, 09:29 AM   #1
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Standard/Vanilla Centos 7 Auditd rules?


Anyone have a link to a 'standard' centos 7 audit.conf file? I imagine it having logging of industry standard security concerns... Im sure that everyone customizes to fit their application... but there must be a standard vanilla config to start from?
 
Old 11-12-2016, 05:46 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by szboardstretcher View Post
Anyone have a link to a 'standard' centos 7 audit.conf file?
If your definition of "vanilla" is package default then it's
Code:
]$ rpm -qf /etc/audit/auditd.conf --qf="... in the %{name} package\n"
or else if you mean compliance then the rule sets are in
Code:
]$ rpm -ql audit|grep \.rule
OK so some rules you couldn't ever dream up but rule sets mostly are common sense things which kind of shows as there's a lot of overlap between CAPP / LSPP / STIG. As with anything just blindly activating a complete rule set isn't what you should do (shouldn't work anyway because it'll b0rk on non-existent items), do tune it to the purpose(s) of the machine(s) or what compliance mandates.
 
1 members found this post helpful.
Old 11-15-2016, 11:20 AM   #3
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Original Poster
Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Exactly what i was searching for.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
The auditd daemon stops logging after deleting audit.log until auditd is restarted Latitude Linux - Security 2 06-20-2013 03:10 PM
Which CentOS 6 download is most like standard RHEL 6? walterbyrd Red Hat 1 11-13-2011 12:05 PM
CentOS and non-standard repositories Galaxy_Stranger Linux - Software 7 05-11-2011 11:05 AM
auditd: auditd startup failed cmschube Red Hat 2 05-11-2009 07:08 AM
LXer: Federal Court Rules Deception in Standard Setting can Violate Antitrust Laws LXer Syndicated Linux News 0 09-07-2007 06:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration