Sujet : auditd
-
The Linux audit framework: writing auditd rules, watching files, and reading the results back
auditd rules live in /etc/audit/rules.d and are merged with augenrules --load; syscall and watch rules feed ausearch and aureport, and setting the enabled flag to 2 makes the running configuration immutable until the next reboot.
Lisible par machine : JSON