1833027 Members
2306 Online
110049 Solutions
New Discussion

Audit mv su and init

 
Rene Mendez_4
Super Advisor

Audit mv su and init


I need audit with trusted su, mv, init, but this system call no is defualt.

how to configure this or how to personalize audith system call

Regards.
Rene
2 REPLIES 2
Sridhar Bhaskarla
Honored Contributor

Re: Audit mv su and init

Hi Rene,

Following are the corresponding system calls.

mv - rename
su - setuid, setgid
init - This does quite a few things. So, I am not sure if you can pick up only few systems calls corresponding to init process

-Sri
You may be disappointed if you fail, but you are doomed if you don't try
Rene Mendez_4
Super Advisor

Re: Audit mv su and init

I prove use de command mv,su check de trusted log and this events no is registred en log.

Regards.
Rene