Jump to content

Talk:Audit framework

From ArchWiki
Latest comment: 6 May by Regid in topic The ids referred by the article

audit.rules

The instructions say to append rule to /etc/audit/audit.rules, but there is no such file on my system. Am I supposed to put rules into an empty file or copy a default from somewhere? Also, systemctl status auditd.service shows augenrules is looking for the directory /etc/audit/rules.d rather than the file mentioned in the instructions, so I'm not even clear whether audit.rules is correct. I don't have the directory either on my machine. --cfr (talk) 16:39, 13 December 2022 (UTC)Reply

From auditd(8), it says "During startup, the rules in /etc/audit/audit.rules are read by auditctl and loaded into the kernel. Alternately, there is also an augenrules program that reads rules located in /etc/audit/rules.d/ and compiles them into an audit.rules file."
So please help double check and update page if you have time. --Fengchao (talk) 03:46, 17 December 2022 (UTC)Reply
As of this writing, Audit_framework#Installation state
/etc/audit/audit.rules: contains the rules and various parameters of the auditd daemon. This file is automatically generated from /etc/audit/rules.d/ by audit-rules.service. See audit.rules(7) and augenrules(8) for details.
As for manually writing rule files under /etc/audit/rules.d/, it can be done. Perhaps a beginner is better following the sequence of operations suggested by Audit_framework#Audit_files_and_directories_access:
  1. Use auditctl to add the rules manually.
  2. Once the rules are validated, add them to a .rules file in /etc/audit/rules.d/.
Regid (talk) 14:15, 6 May 2026 (UTC)Reply

external documentation

I think external documentation is needed in order to novice users could understand how audit tools work. Example this article (Spanish) could provide information for Spaniard users.

—This unsigned comment is by Xan (talk) 08:01, 26 June 2023 (UTC). Please sign your posts with ~~~~!Reply

Revision as of 11:42, 10 August 2024 added a new section of See also containing 3 such external links in English. Striking the header of this discussion as suggested by Help:Discussion#Closing_a_discussion because it seems to be taken care of, and no comments added, almost 21 months ago.

The ids referred by the article

Audit_framework#Which_files_or_syscalls_are_worth-auditing? is referring to ids. Are these ids related to files containing ids in their name from the audispd_plugins package? If they are related, should the audispd_plugins package be mentioned explicitly in Audit_framework#Which_files_or_syscalls_are_worth-auditing?? Regid (talk) 16:03, 6 May 2026 (UTC)Reply