Talk:Audit framework
audit.rules
The instructions say to append rule to /etc/audit/audit.rules, but there is no such file on my system. Am I supposed to put rules into an empty file or copy a default from somewhere? Also, systemctl status auditd.service shows augenrules is looking for the directory /etc/audit/rules.d rather than the file mentioned in the instructions, so I'm not even clear whether audit.rules is correct. I don't have the directory either on my machine. --cfr (talk) 16:39, 13 December 2022 (UTC)
- From auditd(8), it says "During startup, the rules in /etc/audit/audit.rules are read by auditctl and loaded into the kernel. Alternately, there is also an augenrules program that reads rules located in /etc/audit/rules.d/ and compiles them into an audit.rules file."
- So please help double check and update page if you have time. --Fengchao (talk) 03:46, 17 December 2022 (UTC)
- As of this writing, Audit_framework#Installation state
/etc/audit/audit.rules: contains the rules and various parameters of the auditd daemon. This file is automatically generated from/etc/audit/rules.d/byaudit-rules.service. See audit.rules(7) and augenrules(8) for details.
- As for manually writing rule files under
/etc/audit/rules.d/, it can be done. Perhaps a beginner is better following the sequence of operations suggested by Audit_framework#Audit_files_and_directories_access:- Use
auditctlto add the rules manually. - Once the rules are validated, add them to a .rules file in
/etc/audit/rules.d/.
- Use
- Regid (talk) 14:15, 6 May 2026 (UTC)
external documentation
I think external documentation is needed in order to novice users could understand how audit tools work. Example this article (Spanish) could provide information for Spaniard users.
—This unsigned comment is by Xan (talk) 08:01, 26 June 2023 (UTC). Please sign your posts with ~~~~!
- Revision as of 11:42, 10 August 2024 added a new section of See also containing 3 such external links in English. Striking the header of this discussion as suggested by Help:Discussion#Closing_a_discussion because it seems to be taken care of, and no comments added, almost 21 months ago.
The ids referred by the article
Audit_framework#Which_files_or_syscalls_are_worth-auditing? is referring to ids. Are these ids related to files containing ids in their name from the audispd_plugins package? If they are related, should the audispd_plugins package be mentioned explicitly in Audit_framework#Which_files_or_syscalls_are_worth-auditing?? Regid (talk) 16:03, 6 May 2026 (UTC)