All of lore.kernel.org
 help / color / mirror / Atom feed
* Problem with watching power commands - key is not logged
@ 2017-01-28 12:16 Damian Tykałowski
  2017-01-29 21:40 ` Richard Guy Briggs
  0 siblings, 1 reply; 4+ messages in thread
From: Damian Tykałowski @ 2017-01-28 12:16 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1103 bytes --]

Hi

 

I'm struggling to get proper auditing of usage of power commands, here's
what I've got in rules

 

[root@host01 ~]# cat /etc/audit/audit.rules | grep power

-w /sbin/shutdown -p rwx -k power

-w /sbin/poweroff -p rwx -k power

-w /sbin/reboot -p rwx -k power

-w /sbin/halt -p rwx -k power

-w shutdown -p rwx -k power

-w poweroff -p rwx -k power

-w reboot -p rwx -k power

-w halt -p rwx -k power

 

However despite full host reboot/refreshing rules I'm not getting events
with proper key "power"

 

[root@host01 ~]# cat /var/log/audit/audit.log | grep power

<empty>

 

Events are logged though but without key

 

type=USER_CMD msg=audit(1485604576.755:679): pid=3490 uid=5004 auid=5004
ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
msg='cwd="/home/user01" cmd="reboot" terminal=pts/0 res=success'

type=USER_CMD msg=audit(1485604729.923:658): pid=3428 uid=5004 auid=5004
ses=1 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
msg='cwd="/home/user01" cmd="reboot" terminal=pts/0 res=success'

 

Any idea what is wrong? Rules with other keys seems to work.


[-- Attachment #1.2: Type: text/html, Size: 4241 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-01-30 16:32 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-01-28 12:16 Problem with watching power commands - key is not logged Damian Tykałowski
2017-01-29 21:40 ` Richard Guy Briggs
2017-01-30  9:31   ` Damian Tykałowski
2017-01-30 16:32     ` Stephen Buchanan

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.