<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic /var/log/audit/audit.log in Linux in Secure OS Software for Linux</title>
    <link>https://community.hpe.com/t5/secure-os-software-for-linux/var-log-audit-audit-log-in-linux/m-p/4503388#M542</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;We are using auditd for the file system and file changes monitoring and are able to see the log either in /audit.log file or using the ausearch command. We woulk like to use a script or tool which can help us to find specific parameters in the log. Please find below one example and report which we would like to generate automatically.&lt;BR /&gt;&lt;BR /&gt;type=PATH msg=audit(09/23/2009 03:58:50.385:263) : item=1 name=/u01/modprobe.conf inode=49156 dev=fd:02 mode=file,644 ouid=root ogid=root rdev=00:00&lt;BR /&gt;type=PATH msg=audit(09/23/2009 03:58:50.385:263) : item=0 name=/u01/ inode=2 dev=fd:02 mode=dir,755 ouid=root ogid=root rdev=00:00&lt;BR /&gt;type=CWD msg=audit(09/23/2009 03:58:50.385:263) :  cwd=/etc&lt;BR /&gt;type=SYSCALL msg=audit(09/23/2009 03:58:50.385:263) : arch=x86_64 syscall=open success=yes exit=4 a0=14a9ada0 a1=41 a2=81a4 a3=0 items=2 ppid=7524 pid=8533 a&lt;BR /&gt;uid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=21 comm=cp exe=/bin/cp key=u0dir&lt;BR /&gt;&lt;BR /&gt;Manual analysis:-&lt;BR /&gt;Audit log time : 09/23/2009 03:58:50.385:263&lt;BR /&gt;User: root&lt;BR /&gt;Group:root&lt;BR /&gt;File Name: modprobe.conf&lt;BR /&gt;PATH:/u01&lt;BR /&gt;CWD:/etc&lt;BR /&gt;Arch: x86_64&lt;BR /&gt;Success: Yes&lt;BR /&gt;Command: cp&lt;BR /&gt;Command Path:/bin/cp&lt;BR /&gt;Details: Copied file from /etc to /u01&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Gaby</description>
    <pubDate>Fri, 25 Sep 2009 10:14:22 GMT</pubDate>
    <dc:creator>Gaby1110</dc:creator>
    <dc:date>2009-09-25T10:14:22Z</dc:date>
    <item>
      <title>/var/log/audit/audit.log in Linux</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/var-log-audit-audit-log-in-linux/m-p/4503388#M542</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;We are using auditd for the file system and file changes monitoring and are able to see the log either in /audit.log file or using the ausearch command. We woulk like to use a script or tool which can help us to find specific parameters in the log. Please find below one example and report which we would like to generate automatically.&lt;BR /&gt;&lt;BR /&gt;type=PATH msg=audit(09/23/2009 03:58:50.385:263) : item=1 name=/u01/modprobe.conf inode=49156 dev=fd:02 mode=file,644 ouid=root ogid=root rdev=00:00&lt;BR /&gt;type=PATH msg=audit(09/23/2009 03:58:50.385:263) : item=0 name=/u01/ inode=2 dev=fd:02 mode=dir,755 ouid=root ogid=root rdev=00:00&lt;BR /&gt;type=CWD msg=audit(09/23/2009 03:58:50.385:263) :  cwd=/etc&lt;BR /&gt;type=SYSCALL msg=audit(09/23/2009 03:58:50.385:263) : arch=x86_64 syscall=open success=yes exit=4 a0=14a9ada0 a1=41 a2=81a4 a3=0 items=2 ppid=7524 pid=8533 a&lt;BR /&gt;uid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=21 comm=cp exe=/bin/cp key=u0dir&lt;BR /&gt;&lt;BR /&gt;Manual analysis:-&lt;BR /&gt;Audit log time : 09/23/2009 03:58:50.385:263&lt;BR /&gt;User: root&lt;BR /&gt;Group:root&lt;BR /&gt;File Name: modprobe.conf&lt;BR /&gt;PATH:/u01&lt;BR /&gt;CWD:/etc&lt;BR /&gt;Arch: x86_64&lt;BR /&gt;Success: Yes&lt;BR /&gt;Command: cp&lt;BR /&gt;Command Path:/bin/cp&lt;BR /&gt;Details: Copied file from /etc to /u01&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Gaby</description>
      <pubDate>Fri, 25 Sep 2009 10:14:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/var-log-audit-audit-log-in-linux/m-p/4503388#M542</guid>
      <dc:creator>Gaby1110</dc:creator>
      <dc:date>2009-09-25T10:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/audit/audit.log in Linux</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/var-log-audit-audit-log-in-linux/m-p/4503389#M543</link>
      <description>Plase see this link, it may help:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://people.redhat.com/sgrubb/audit/visualize/index.html" target="_blank"&gt;http://people.redhat.com/sgrubb/audit/visualize/index.html&lt;/A&gt;</description>
      <pubDate>Fri, 25 Sep 2009 14:14:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/var-log-audit-audit-log-in-linux/m-p/4503389#M543</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2009-09-25T14:14:26Z</dc:date>
    </item>
  </channel>
</rss>

