All of lore.kernel.org
 help / color / mirror / Atom feed
* RHEL6 and RHEL7 audispatch configurations
@ 2017-04-03 18:23 warron.french
  2017-04-03 22:34 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: warron.french @ 2017-04-03 18:23 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 979 bytes --]

Hi Steve, sorry for bugging you directly, nearly 1 year ago (May 10th to be
exact) we collaborated, for my benefit on how to configure audispatch on
"RHEL6" machines.

It seems that my instructions that I kept from 1 year ago are no longer
valid; there are new files in existence and some old ones no longer in
existence for both RHEL6 and RHEL7:


*[OLD]*
/etc/audisp/
*audisp-remote.conf,*
/etc/audisp/plugins.d/*au-remote.conf*


*[NEW]*
/etc/audisp/plugins.d/af_unix.conf
/etc/audisp/plugins.d/syslog.conf

Not sure how to find the appropriate man pages to configure this setup
properly.  I am attaching what I wrote 1 year ago; and hope that you can
push me in the direction of a good walk-through for audispatch of the
modern revision (audit-2.4.5-3 on RHEL6, and audit-2.4.1-5.el7).

I have to stick with these revision for a little while since we are going
through a Project Management Stage gate, impacting update decisions.




--------------------------
Warron French

[-- Attachment #1.2: Type: text/html, Size: 1549 bytes --]

[-- Attachment #2: DOCS-02-Configure Centralized AUDIT-logging with audispatch.docx --]
[-- Type: application/vnd.openxmlformats-officedocument.wordprocessingml.document, Size: 28091 bytes --]

[-- Attachment #3: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2017-04-03 22:34 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-04-03 18:23 RHEL6 and RHEL7 audispatch configurations warron.french
2017-04-03 22:34 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.