Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 18 Sep 2006 15:16:20 +0900
From:      Ganbold <ganbold@micom.mng.net>
To:        Robert Watson <rwatson@FreeBSD.org>
Cc:        Joerg Pernfuss <elessar@bsdforen.de>, stable@FreeBSD.org, Cristiano Deana <cristiano.deana@gmail.com>
Subject:   Re: Problems with auditd -- resolved
Message-ID:  <450E39B4.2000105@micom.mng.net>
In-Reply-To: <20060917091750.T74654@fledge.watson.org>
References:  <20060917091750.T74654@fledge.watson.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Robert Watson wrote:
>
> Dear all,
>
> I've just comitted a fix to syscalls.master and regenerated the 
> remaining system call files, which should correct the auditctl: 
> Invalid Argument error being returned by auditd.  In short order, this 
> fix should be on the cvsup mirrors -- please let me know if it 
> resolves the problem you were experiencing.

Hi,

After installing and running auditd I don't see any log files for auditd:

daemon# ls -l /var/audit/
total 0
-r--r-----  1 root  audit  0 Sep 18 14:23 20060918052316.20060918060339
-r--r-----  1 root  audit  0 Sep 18 15:03 20060918060339.not_terminated

I have custom /etc/security/audit_control and audit_user files.

daemon# more /etc/security/audit_control
#
# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_control#3 $
# $FreeBSD: src/contrib/openbsm/etc/audit_control,v 1.2.2.1 2006/09/02 
10:46:00 rwatson Exp $
#
dir:/var/audit
flags:all
minfree:20
naflags:lo

#
# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_user#3 $
# $FreeBSD: src/contrib/openbsm/etc/audit_user,v 1.2.2.1 2006/09/02 
10:46:00 rwatson Exp $
#
#root:lo:no
root:all:no

I'm bit confused here I thought auditd should log all activities, but I 
don't see any log files.
Am I doing something wrong here or my understanding regarding auditd is 
wrong?

thanks in advance,

Ganbold


>
> Thanks,
>
> Robert N M Watson
> Computer Laboratory
> University of Cambridge
> _______________________________________________
> freebsd-stable@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-stable
> To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org"
>
>
>




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?450E39B4.2000105>