Rules
Youtube tutorial
Defult rules repo
ausearch
Ausearch Docs - a tool to query audit daemon logs
Record types/Messages -m
The event type is specified in the type=
field at the beginning of
every Audit record.
Keys -k
Listing exisiting keys
U can add new keys with
And query by them
Succes value -sv
Use the -m option to identify specific messages and -sv
to define the
success value.
Selinux Logs
[Selinux MAIN]({{\< ref “posts/SELinux.md#logging”>}})
Summary
search for executubles
Ausyscall
It gives u description of the syscall
Example