auditd audispd auditctl autrace ausearch aureport

    1. [root@rmaster01 ~]# rpm -qa audit
    2. audit-2.8.5-4.el7.x86_64
    3. [root@rmaster01 ~]# rpm -ql audit
    4. /etc/audisp
    5. /etc/audisp/audispd.conf
    6. /etc/audisp/plugins.d
    7. /etc/audisp/plugins.d/af_unix.conf
    8. /etc/audisp/plugins.d/syslog.conf
    9. /etc/audit
    10. /etc/audit/audit-stop.rules
    11. /etc/audit/audit.rules
    12. /etc/audit/auditd.conf
    13. /etc/audit/rules.d
    14. /etc/audit/rules.d/audit.rules
    15. /sbin/audispd
    16. /sbin/auditctl
    17. /sbin/auditd
    18. /sbin/augenrules
    19. /sbin/aureport
    20. /sbin/ausearch
    21. /sbin/autrace
    22. /usr/bin/aulast
    23. /usr/bin/aulastlog
    24. /usr/bin/ausyscall
    25. /usr/bin/auvirt
    26. /usr/lib/systemd/system/auditd.service
    27. /usr/libexec/initscripts/legacy-actions/auditd
    28. /usr/libexec/initscripts/legacy-actions/auditd/condrestart
    29. /usr/libexec/initscripts/legacy-actions/auditd/reload
    30. /usr/libexec/initscripts/legacy-actions/auditd/restart
    31. /usr/libexec/initscripts/legacy-actions/auditd/resume
    32. /usr/libexec/initscripts/legacy-actions/auditd/rotate
    33. /usr/libexec/initscripts/legacy-actions/auditd/state
    34. /usr/libexec/initscripts/legacy-actions/auditd/stop
    35. /usr/share/doc/audit-2.8.5
    36. /usr/share/doc/audit-2.8.5/COPYING
    37. /usr/share/doc/audit-2.8.5/ChangeLog
    38. /usr/share/doc/audit-2.8.5/README
    39. /usr/share/doc/audit-2.8.5/auditd.cron
    40. /usr/share/doc/audit-2.8.5/rules
    41. /usr/share/doc/audit-2.8.5/rules/10-base-config.rules
    42. /usr/share/doc/audit-2.8.5/rules/10-no-audit.rules
    43. /usr/share/doc/audit-2.8.5/rules/11-loginuid.rules
    44. /usr/share/doc/audit-2.8.5/rules/12-cont-fail.rules
    45. /usr/share/doc/audit-2.8.5/rules/12-ignore-error.rules
    46. /usr/share/doc/audit-2.8.5/rules/20-dont-audit.rules
    47. /usr/share/doc/audit-2.8.5/rules/21-no32bit.rules
    48. /usr/share/doc/audit-2.8.5/rules/22-ignore-chrony.rules
    49. /usr/share/doc/audit-2.8.5/rules/23-ignore-filesystems.rules
    50. /usr/share/doc/audit-2.8.5/rules/30-nispom.rules
    51. /usr/share/doc/audit-2.8.5/rules/30-ospp-v42.rules
    52. /usr/share/doc/audit-2.8.5/rules/30-pci-dss-v31.rules
    53. /usr/share/doc/audit-2.8.5/rules/30-stig.rules
    54. /usr/share/doc/audit-2.8.5/rules/31-privileged.rules
    55. /usr/share/doc/audit-2.8.5/rules/32-power-abuse.rules
    56. /usr/share/doc/audit-2.8.5/rules/40-local.rules
    57. /usr/share/doc/audit-2.8.5/rules/41-containers.rules
    58. /usr/share/doc/audit-2.8.5/rules/42-injection.rules
    59. /usr/share/doc/audit-2.8.5/rules/43-module-load.rules
    60. /usr/share/doc/audit-2.8.5/rules/70-einval.rules
    61. /usr/share/doc/audit-2.8.5/rules/71-networking.rules
    62. /usr/share/doc/audit-2.8.5/rules/99-finalize.rules
    63. /usr/share/doc/audit-2.8.5/rules/README-rules
    64. /usr/share/man/man5/audispd.conf.5.gz
    65. /usr/share/man/man5/auditd.conf.5.gz
    66. /usr/share/man/man5/ausearch-expression.5.gz
    67. /usr/share/man/man7/audit.rules.7.gz
    68. /usr/share/man/man8/audispd.8.gz
    69. /usr/share/man/man8/auditctl.8.gz
    70. /usr/share/man/man8/auditd.8.gz
    71. /usr/share/man/man8/augenrules.8.gz
    72. /usr/share/man/man8/aulast.8.gz
    73. /usr/share/man/man8/aulastlog.8.gz
    74. /usr/share/man/man8/aureport.8.gz
    75. /usr/share/man/man8/ausearch.8.gz
    76. /usr/share/man/man8/ausyscall.8.gz
    77. /usr/share/man/man8/autrace.8.gz
    78. /usr/share/man/man8/auvirt.8.gz
    79. /var/log/audit
    80. /var/run/auditd.state
    81. [root@rmaster01 ~]#
    1. [root@rmaster01 ~]# systemctl status auditd.service
    2. auditd.service - Security Auditing Service
    3. Loaded: loaded (/usr/lib/systemd/system/auditd.service; enabled; vendor preset: enabled)
    4. Active: active (running) since Sun 2021-03-21 14:17:37 CST; 1 months 11 days ago
    5. Docs: man:auditd(8)
    6. https://github.com/linux-audit/audit-documentation
    7. Main PID: 617 (auditd)
    8. Tasks: 2
    9. Memory: 2.5M
    10. CGroup: /system.slice/auditd.service
    11. └─617 /sbin/auditd
    12. Mar 21 14:17:37 rmaster01 augenrules[621]: enabled 1
    13. Mar 21 14:17:37 rmaster01 augenrules[621]: failure 1
    14. Mar 21 14:17:37 rmaster01 augenrules[621]: pid 617
    15. Mar 21 14:17:37 rmaster01 augenrules[621]: rate_limit 0
    16. Mar 21 14:17:37 rmaster01 augenrules[621]: backlog_limit 8192
    17. Mar 21 14:17:37 rmaster01 augenrules[621]: lost 0
    18. Mar 21 14:17:37 rmaster01 augenrules[621]: backlog 1
    19. Mar 21 14:17:37 rmaster01 systemd[1]: Started Security Auditing Service.
    20. Mar 28 12:01:01 rmaster01 auditd[617]: Audit daemon rotating log files
    21. Apr 18 01:50:01 rmaster01 auditd[617]: Audit daemon rotating log files
    22. [root@rmaster01 ~]#
    1. [root@rmaster01 ~]# auditctl -help
    2. usage: auditctl [options]
    3. -a <l,a> Append rule to end of <l>ist with <a>ction
    4. -A <l,a> Add rule at beginning of <l>ist with <a>ction
    5. -b <backlog> Set max number of outstanding audit buffers
    6. allowed Default=64
    7. -c Continue through errors in rules
    8. -C f=f Compare collected fields if available:
    9. Field name, operator(=,!=), field name
    10. -d <l,a> Delete rule from <l>ist with <a>ction
    11. l=task,exit,user,exclude
    12. a=never,always
    13. -D Delete all rules and watches
    14. -e [0..2] Set enabled flag
    15. -f [0..2] Set failure flag
    16. 0=silent 1=printk 2=panic
    17. -F f=v Build rule: field name, operator(=,!=,<,>,<=,
    18. >=,&,&=) value
    19. -h Help
    20. -i Ignore errors when reading rules from file
    21. -k <key> Set filter key on audit rule
    22. -l List rules
    23. -m text Send a user-space message
    24. -p [r|w|x|a] Set permissions filter on watch
    25. r=read, w=write, x=execute, a=attribute
    26. -q <mount,subtree> make subtree part of mount point's dir watches
    27. -r <rate> Set limit in messages/sec (0=none)
    28. -R <file> read rules from file
    29. -s Report status
    30. -S syscall Build rule: syscall name or number
    31. -t Trim directory watches
    32. -v Version
    33. -w <path> Insert watch at <path>
    34. -W <path> Remove watch at <path>
    35. --loginuid-immutable Make loginuids unchangeable once set
    36. --reset-lost Reset the lost record counter
    37. [root@rmaster01 ~]#