linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* The format of password change audit events seems to have changed, Can you confirm the correct record type ?
@ 2021-07-08 18:19 Wieprecht, Karen M.
  2021-07-08 19:23 ` Steve Grubb
  0 siblings, 1 reply; 8+ messages in thread
From: Wieprecht, Karen M. @ 2021-07-08 18:19 UTC (permalink / raw)
  To: Linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1448 bytes --]

I've noticed that the messages I'm searching  for in splunk to show root password changes no longer seem to be in the same format.  Most of our systems run RHEL7 release 7.9,  and I believe this is a recent change (I've only noticed this problem in the past 3 months or so?), but we do have an older 7.5 system, so  I was able to use that to compare against  the 7.5 to  identify what's changed.    I wanted to confirm which record I should be using now since there are several that get generated now

The key differences seem to be in the message generated and the keyname being used for the account being targeted,  but I wanted to confirm that there isn't some other record I should be looking at to verify that the root password was changed in the required timeframe since I see several records being generated from a password change, none of which include anything as conclusive as the old message that showed the operation as a "password change".   Here are some fo the fields I'm looking at:

type=USER_CHAUTHOK
exe=/usr/bin/passwd
[acct targeted for the passwd change]:
            id=root          (old format)
            acct=root      (latest format)
msg
           msg='op=change password  (old format)
           msg='op=PAM:chauthok      (latest format)

If you can  confirm whether this is the info I should be using now to confirm password changes, that would be much appreciated.

Thanks so much,
Karen Wieprecht

[-- Attachment #1.2: Type: text/html, Size: 4435 bytes --]

[-- Attachment #2: Type: text/plain, Size: 106 bytes --]

--
Linux-audit mailing list
Linux-audit@redhat.com
https://listman.redhat.com/mailman/listinfo/linux-audit

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2021-07-10 14:59 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-07-08 18:19 The format of password change audit events seems to have changed, Can you confirm the correct record type ? Wieprecht, Karen M.
2021-07-08 19:23 ` Steve Grubb
2021-07-08 22:53   ` warron.french
2021-07-09  0:46     ` Richard Guy Briggs
2021-07-09 12:06       ` warron.french
2021-07-09 13:18       ` [EXT] " Wieprecht, Karen M.
2021-07-09 14:22     ` Wieprecht, Karen M.
2021-07-10 14:57     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).