From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Limiting SECCOMP audit events Date: Wed, 13 Dec 2017 18:58:46 -0500 Message-ID: <58203247.sCqcla2mis@x2> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============3315810385792112238==" Return-path: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Linux Audit List-Id: linux-audit@redhat.com This is a multi-part message in MIME format. --===============3315810385792112238== Content-Type: multipart/alternative; boundary="nextPart4289593.71cxdu7Dxe" Content-Transfer-Encoding: 7Bit This is a multi-part message in MIME format. --nextPart4289593.71cxdu7Dxe Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" Hello, Over the last month, the amount of seccomp events in audit logs is sky-rocketing. I have over a million events in the last 2 days. Most of this is generated by firefox and qt webkit. I am wondering if the audit package should ship a file for /usr/lib/sysctl.d/60-auditd.conf wherein it has kernel.seccomp.actions_logged = kill_process kill_thread errno Also, has anyone verified this sysctl is filtering audit events? Even with the above, I have over a million events on a 4.14.3 kernel. Firefox alone is generating over 50,000 events per hour. Thanks, -Steve --nextPart4289593.71cxdu7Dxe Content-Transfer-Encoding: 7Bit Content-Type: text/html; charset="us-ascii"

Hello,

 

Over the last month, the amount of seccomp events in audit logs is sky-rocketing. I have over a million events in the last 2 days. Most of this is generated by firefox and qt webkit.

 

I am wondering if the audit package should ship a file for

 

/usr/lib/sysctl.d/60-auditd.conf

 

wherein it has

 

kernel.seccomp.actions_logged = kill_process kill_thread errno

 

Also, has anyone verified this sysctl is filtering audit events? Even with the above, I have over a million events on a 4.14.3 kernel. Firefox alone is generating over 50,000 events per hour.

 

Thanks,

-Steve

--nextPart4289593.71cxdu7Dxe-- --===============3315810385792112238== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3315810385792112238==--