auditing subsystem

From: Russell Miller (rmiller_at_duskglow.com)
Date: 03/04/05

  • Next message: Andrew Morton: "Re: [PATCH] trivial fix for 2.6.11 raid6 compilation on ppc w/ Altivec"
    To: linux-kernel@vger.kernel.org
    Date:	Thu, 3 Mar 2005 22:18:11 -0800
    
    

    I've been doing a lot of research on this, and I keep coming up with things
    that don't work, have been abandoned, or are almost impossible to find or get
    working. So I'll ask here. Maybe one of the ultra-elightened linux gods
    will have a ready answer.

    I want to be able to audit system calls - I want to log when files are opened,
    created, changed, deleted, etc. Preferably I would like to do it without
    having to apply kernel patches, using vanilla (or close to vanilla) kernel.
    If this isn't possible, my net preference is to use a module. If this isn't
    possible, well, I'll do what I have to.

    I notice there is a CONFIG_AUDIT option. Is this what I am looking for, and
    how do I use it? /dev/audit seems not to work...

    Thanks. If you can even point me a suitable FM to R, I'd be content.

    --Russell

    -- 
    Russell Miller - rmiller@duskglow.com - Agoura, CA
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at  http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at  http://www.tux.org/lkml/
    

  • Next message: Andrew Morton: "Re: [PATCH] trivial fix for 2.6.11 raid6 compilation on ppc w/ Altivec"

    Relevant Pages

    • Re: Lockups with 2.4.22 on a dual P3/Katmai
      ... > the vanilla 2.4.23-pre1 kernels. ... > the system locks up after about half an hour to two hours (doesn't seem ... The reset button will, however, reset ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Linux GPL and binary module exception clause?
      ... of them for every exported symbol in turn, ... hacked -E:) we don't need to compile for this, ... `...some suburbanite DSL customer who thinks kernel patches are some ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Severe I/O performance regression 2.6.6 to 2.6.7 or 2.6.8-rc3
      ... > vanilla 2.6.6 kernel. ... This is the closest it appears to be possible to narrow down where the ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [VIA-RHINE] Timeouts on EP-HDA3+ Motherboard
      ... On 10.08.2004 09:06, Roger Luethi wrote: ... >>The box is currently running 2.6.7 vanilla. ... my standard test (copying a 680MB ISO image from/to Samba shares in ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [SATA] libata-dev queue updated
      ... >>This means we have eliminated libata as a problem source, ... * 2.6.11 vanilla does not work ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)