diff options
author | Hendrik Jäger <gitcommit@henk.geekmail.org> | 2021-05-03 23:42:49 +0300 |
---|---|---|
committer | Hendrik Jäger <gitcommit@henk.geekmail.org> | 2021-05-03 23:42:49 +0300 |
commit | 8f5f4ceab8ae3629ec27827982d861ecad3366ca (patch) | |
tree | 46d43d7dc9fcf17542b53f0f23bfcfddcfdd4cf5 | |
parent | cf985884dae8da4d10587bc3bb38389e8e90e8db (diff) |
Update logcheck rules for auditd
-rw-r--r-- | files/etc/logcheck/ignore.d.server/local-auditd | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/files/etc/logcheck/ignore.d.server/local-auditd b/files/etc/logcheck/ignore.d.server/local-auditd index 845e5cf..3694ba2 100644 --- a/files/etc/logcheck/ignore.d.server/local-auditd +++ b/files/etc/logcheck/ignore.d.server/local-auditd @@ -1,5 +1,5 @@ type=CRED_ACQ msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=pam_permit acct="(root|logcheck|daemon|www-data)" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ -type=CRED_DISP msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=pam_permit acct="(www-data|logcheck)" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ +type=CRED_DISP msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=pam_permit acct="(root|www-data|logcheck|daemon)" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ type=LOGIN msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 subj==unconfined old-auid=[[:digit:]]+ auid=(0|1|33|108) tty=\(none\) old-ses=[[:digit:]]+ ses=[[:digit:]]+ res=1$ type=USER_ACCT msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=PAM:accounting grantors=pam_permit acct="root" exe="/usr/bin/sudo" hostname=\? addr=\? terminal=/dev/pts/[[:digit:]]+ res=success'$ type=USER_ACCT msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:accounting grantors=pam_permit acct="(root|logcheck|daemon|www-data)" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ @@ -7,7 +7,7 @@ type=USER_AUTH msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digi type=USER_CHAUTHTOK msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=display aging info id=[[:digit:]]+ exe="/usr/bin/chage" hostname=\? addr=\? terminal=\? res=success'$ type=USER_CMD msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='cwd="/etc/puppet" cmd=[[:xdigit:]]+ terminal=pts/[[:digit:]]+ res=success$ type=USER_ERR msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=PAM:bad_ident grantors=\? acct="\?" exe="/usr/sbin/sshd" hostname=[[:xdigit:]:.]+ addr=[[:xdigit:]:.]+ terminal=ssh res=failed'$ -type=USER_LOGIN msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=login acct=[[:digit:]]+ exe="/usr/sbin/sshd" hostname=\? addr=[[:xdigit:]:.]+ terminal=sshd res=failed'$ +type=USER_LOGIN msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=login acct=[[:alnum:]]+ exe="/usr/sbin/sshd" hostname=\? addr=[[:xdigit:]:.]+ terminal=sshd res=failed'$ type=USER_START msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=(0|1|33|108) ses=[[:digit:]]+ subj==unconfined msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_env,pam_permit,pam_unix,pam_limits acct="[[:alnum:]]+" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ type=USER_END msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=(0|1|33|108) ses=[[:digit:]]+ subj==unconfined msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_env,pam_permit,pam_unix,pam_limits acct="[[:alnum:]]+" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ auditd\[[[:digit:]]+\]: Audit daemon rotating log files$ |