Tips from an RHCE: Visualizing audit logs with mkbar

Posted by Sander_Marechal on Jan 22, 2008 9:31 PM EDT
Red Hat Magazine
Mail this story
Print this story

The 2.6 Linux kernel comes with a very flexible and powerful auditing subsystem called auditd. auditd is composed of two parts. The main work is done in kernel-space. In user-land, auditd is listening for generated audit events. auditd is able to log file-watches as well as syscalls. All LSM-based subsystems–for example, SELinux–are logging via auditd as well.

Full Story

  Nav
» Read more about: Story Type: News Story; Groups: Kernel, Linux, Red Hat

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.