LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-22-2009, 02:17 PM   #1
pschweitzer
LQ Newbie
 
Registered: Apr 2009
Posts: 2

Rep: Reputation: 0
where to get auditd, auditctl for slack 12.x


It looks like I will need to audit a variety of events and configure the logging of those events. I can easily enable the kernel features but I don't know where to get the utilities (auditd, auditctl) in a form suitable for installation on Slackware 12.x. Most of my systems run 12.1 at present, a few run 12.2. I'm comfortable building stuff from source, it just isn't clear to me where to find these utilities.

Anyone care to offer a little guidance? Anyone else use these?
 
Old 04-22-2009, 03:24 PM   #2
mostlyharmless
Senior Member
 
Registered: Jan 2008
Distribution: Arch/Manjaro, might try Slackware again
Posts: 1,851
Blog Entries: 14

Rep: Reputation: 284Reputation: 284Reputation: 284
It's my impression that auditd is part of the whole SELinux package, which might be more than you want to bite off and chew. You could try alien on the ubuntu package, I suppose: http://packages.ubuntu.com/gutsy-updates/admin/auditd

As for the source, since it's a userspace utility it'll probably be here:
http://userspace.selinuxproject.org/trac/wiki/Releases

Hope that helps, I really don't have a clue.

Last edited by mostlyharmless; 04-22-2009 at 03:26 PM.
 
Old 04-22-2009, 04:11 PM   #3
pschweitzer
LQ Newbie
 
Registered: Apr 2009
Posts: 2

Original Poster
Rep: Reputation: 0
where to get auditd, auditctl for slack 12.x

Thanks! That link to selinux might come in handy depending on how much of the infrastructure I really need. It looks like I might be able to work with the source code package from http://people.redhat.com/sgrubb/audit/ for the most basic parts of the package. My first attempt to find the source of this code took me to a site in Austria, and it wasn't clear to me where the home base of auditd actually was.

But I'll begin to explore that selinux site to see if there are other bits that I need to run. As a longtime Slackware user, I prefer things to be simple, but sometimes more stuff must be added ;-)
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
auditd: auditd startup failed cmschube Red Hat 2 05-11-2009 07:08 AM
atarting auditd fail akeker Linux - General 1 09-21-2008 03:46 AM
Debian auditctl package fullgore Linux - Software 0 05-26-2008 03:41 PM
auditd and laus kronixx Red Hat 0 07-15-2005 05:33 PM
Help with crond and auditd pfaendtner Linux - Software 4 04-25-2005 10:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 02:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration