All of lore.kernel.org
 help / color / mirror / Atom feed
* New draft standards
@ 2015-12-08 19:22 Steve Grubb
  2015-12-08 19:58 ` Paul Moore
  2015-12-08 20:49 ` Richard Guy Briggs
  0 siblings, 2 replies; 25+ messages in thread
From: Steve Grubb @ 2015-12-08 19:22 UTC (permalink / raw)
  To: linux-audit

Hello,

I would like to point out 2 new standards that have been posted to the linux 
audit web page. The first establishes the events around system start up and 
shutdown. This is important because it sets the session boundaries for when a 
system is up or down or crashed.

http://people.redhat.com/sgrubb/audit/system-lifecycle.txt

The second standard is more of a forward looking standard. It explains how the 
audit daemon and utilities will perform event enrichment before being stored 
long term in an aggregator. The target for implementation is the 2.5 release 
of the audit daemon.

http://people.redhat.com/sgrubb/audit/event-enrichment

Let me know if anyone has feedback on these standards, especially the second 
one.

-Steve

^ permalink raw reply	[flat|nested] 25+ messages in thread

end of thread, other threads:[~2015-12-29 19:28 UTC | newest]

Thread overview: 25+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-12-08 19:22 New draft standards Steve Grubb
2015-12-08 19:58 ` Paul Moore
2015-12-08 20:25   ` Steve Grubb
2015-12-09  0:28     ` Paul Moore
2015-12-09  1:43       ` Burn Alting
2015-12-10 22:49         ` Steve Grubb
2015-12-10 22:59           ` Paul Moore
2015-12-15  5:11             ` Richard Guy Briggs
2015-12-10  4:35       ` Steve Grubb
2015-12-10 16:50         ` Paul Moore
2015-12-10 17:40         ` F Rafi
2015-12-14 15:34           ` Steve Grubb
2015-12-14 16:38             ` Joe Wulf
2015-12-14 17:01               ` Kevin.Dienst
2015-12-14 22:12                 ` Burn Alting
2015-12-15 13:46                   ` Steve Grubb
2015-12-18  5:12                     ` Burn Alting
2015-12-23 22:44                       ` Burn Alting
2015-12-26 16:38                         ` Steve Grubb
2015-12-27  0:30                           ` Burn Alting
2015-12-27 15:06                             ` Steve Grubb
2015-12-28  7:24                               ` Burn Alting
2015-12-29 19:28             ` LC Bruzenak
2015-12-08 20:49 ` Richard Guy Briggs
2015-12-08 21:28   ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.