diff options
author | Hendrik Jäger <gitcommit@henk.geekmail.org> | 2021-05-04 23:38:54 +0300 |
---|---|---|
committer | Hendrik Jäger <gitcommit@henk.geekmail.org> | 2021-05-04 23:38:54 +0300 |
commit | c16f4eaedb36c87c75cca582cf2580fa5a29b0f9 (patch) | |
tree | bec0f1b5b999968b962338ecd6b2b088b544f0b5 /files/etc | |
parent | 6da2616aaf2c643a8ee28713ca9b02ab704b6a05 (diff) |
Update logcheck rules for auditd
Diffstat (limited to 'files/etc')
-rw-r--r-- | files/etc/logcheck/ignore.d.server/local-auditd | 7 |
1 files changed, 3 insertions, 4 deletions
diff --git a/files/etc/logcheck/ignore.d.server/local-auditd b/files/etc/logcheck/ignore.d.server/local-auditd index 3db2f11..afe26ec 100644 --- a/files/etc/logcheck/ignore.d.server/local-auditd +++ b/files/etc/logcheck/ignore.d.server/local-auditd @@ -1,8 +1,7 @@ -type=CRED_ACQ msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=(pam_[[:alnum:]]+,?)+ acct="[[:alnum:]@-]+" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ -type=CRED_DISP msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=pam_permit acct="[[:alnum:]@-]+" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ +type=CRED_ACQ msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=(pam_[[:alnum:]]+,?)+ acct="[[:alnum:]@-]+" exe="[^"]+" hostname=\? addr=\? terminal=(cron|ssh) res=success'$ +type=CRED_DISP msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:setcred grantors=pam_permit acct="[[:alnum:]@-]+" exe="[^"]+" hostname=\? addr=\? terminal=(cron|ssh) res=success'$ type=LOGIN msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 subj==unconfined old-auid=[[:digit:]]+ auid=[[:digit:]]+ tty=\(none\) old-ses=[[:digit:]]+ ses=[[:digit:]]+ res=1$ -type=USER_ACCT msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=PAM:accounting grantors=pam_permit acct="root" exe="/usr/bin/sudo" hostname=\? addr=\? terminal=/dev/pts/[[:digit:]]+ res=success'$ -type=USER_ACCT msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:accounting grantors=pam_permit acct="[[:alnum:]@-]+" exe="/usr/sbin/cron" hostname=\? addr=\? terminal=cron res=success'$ +type=USER_ACCT msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:accounting grantors=pam_permit acct="[[:alnum:]@-]+" exe="[^"]+" hostname=\? addr=\? terminal=[[:alnum:]/]+ res=success'$ type=USER_AUTH msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=[[:digit:]]+ ses=[[:digit:]]+ subj==unconfined msg='op=PAM:authentication grantors=\? acct="[[:alnum:]@-]+" exe="[^"]*" hostname=[[:xdigit:]:.]+ addr=[[:xdigit:]:.]+ terminal=(ssh|dovecot) res=(failed|success)'$ type=USER_CHAUTHTOK msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='op=display aging info id=[[:digit:]]+ exe="/usr/bin/chage" hostname=\? addr=\? terminal=\? res=success'$ type=USER_CMD msg=audit\([[:digit:]]+\.[[:digit:]]+:[[:digit:]]+\): pid=[[:digit:]]+ uid=0 auid=0 ses=[[:digit:]]+ subj==unconfined msg='cwd="/etc/puppet" cmd=[[:xdigit:]]+ terminal=pts/[[:digit:]]+ res=success$ |