linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Unhelpful events
@ 2021-06-07 15:32 Steve Grubb
  2021-06-07 17:42 ` Richard Guy Briggs
  0 siblings, 1 reply; 4+ messages in thread
From: Steve Grubb @ 2021-06-07 15:32 UTC (permalink / raw)
  To: linux-audit

Hello,

While patching up the event normalizer, I run across these events which 
really have no useful information:

type=BPF msg=audit(1622913714.840:15017): prog-id=137 op=UNLOAD

type=TIME_INJOFFSET msg=audit(1622547739.500:4): sec=0 nsec=486383948

type=NETFILTER_CFG msg=audit(06/06/2021 08:44:53.947:976) : table=filter 
family=bridge entries=0 op=xt_unregister pid=5833 
subj=system_u:system_r:kernel_t:s0 comm=kworker/u16:3

Either their syscall record is missing or they simply do not have all the 
necessary information. (Subject, action, object, results)

-Steve


--
Linux-audit mailing list
Linux-audit@redhat.com
https://listman.redhat.com/mailman/listinfo/linux-audit


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-06-07 19:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-06-07 15:32 Unhelpful events Steve Grubb
2021-06-07 17:42 ` Richard Guy Briggs
2021-06-07 18:38   ` Steve Grubb
2021-06-07 19:22     ` Richard Guy Briggs

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).