Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

create a new template for audit watches #12827

Open
vojtapolasek opened this issue Jan 15, 2025 · 0 comments
Open

create a new template for audit watches #12827

vojtapolasek opened this issue Jan 15, 2025 · 0 comments

Comments

@vojtapolasek
Copy link
Collaborator

Currently, there is a template for audit watches, called audit_rules_watch.
This template uses the -w rule parameter. Citing Audit.rules man page:

Watches can also be created using the deprecated −w format which allows for backwards compatibility at the expense of system performance as explained. Using syscall rules as shown above, you can choose between path and dir which is against a specific inode or directory tree respectively. It should also be noted that the recursive directory watch will stop if there is a mount point below the parent directory. There is an option to make the mounted subdirectory equivalent by using a -q rule.

there should be a template which uses the new format, e.g.

−a always,exit −F arch=b64 -F path=path-to-file -F perm=permissions -F key=keyname
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant