On 2017-07-25 14:14, Paul Moore wrote:
> On Mon, Jul 24, 2017 at 11:48 PM, Richard Guy Briggs <[email protected]> wrote:
> > On 2017-07-24 11:52, Steve Grubb wrote:
> >> On Monday, July 24, 2017 10:40:08 AM EDT Richard Guy Briggs wrote:
> >> > Add a column to indicate the source of the message, including indicating
> >> > whether or not it is related to syscalls.
> >> >
> >> > Column name: SOURCE
> >> > Key:
> >> >         CTL     Control messages, usually initiated by audit daemon.
> >>
> >> Most of these come from auditctl. Auditd only sends enable and setpid.
> >
> > I had considered auditctl as part of the audit daemon, as opposed to
> > pam, systemd, vsftpd et al that supply user event messages, though I
> > suppose even systemd wants to play audit controller too ...
> 
> I think trying to chase down which application is trying to manage the
> audit subsystem is a losing battle.  In fact, I honestly would
> probably shrink this "source" list down to just a few possible values:
> kernel, userspace, and control.  I'm not convinced that granularity
> below this level is particularly useful, and could be confusing.

So I'm guessing from this comment that you think one column is
sufficient?  I'd really like to further break "kernel" down into
"syscall" and "independent/autonomous".

> paul moore

- RGB

--
Richard Guy Briggs <[email protected]>
Sr. S/W Engineer, Kernel Security, Base Operating Systems
Remote, Ottawa, Red Hat Canada
IRC: rgb, SunRaycer
Voice: +1.647.777.2635, Internal: (81) 32635

--
Linux-audit mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/linux-audit

Reply via email to