Re: iptables changes triggering audit messages, despite auditd not being installed

2016-05-05 Thread shawn wilson
On May 5, 2016 8:10 AM, "Tony Evans" wrote: > > Firstly, apologies for double-posting the issue originally. > > On 5 May 2016 at 13:05, shawn wilson wrote: > > > > On May 5, 2016 6:03 AM, "Tony Evans" wrote: > >> > > > >> I can't find why the log entries are being created (i.e. I know the > >> t

Re: iptables changes triggering audit messages, despite auditd not being installed

2016-05-05 Thread Tony Evans
Firstly, apologies for double-posting the issue originally. On 5 May 2016 at 13:05, shawn wilson wrote: > > On May 5, 2016 6:03 AM, "Tony Evans" wrote: >> > >> I can't find why the log entries are being created (i.e. I know the >> trigger, but I can't work out why that trigger is now generating

Re: iptables changes triggering audit messages, despite auditd not being installed

2016-05-05 Thread shawn wilson
On May 5, 2016 6:03 AM, "Tony Evans" wrote: > > I can't find why the log entries are being created (i.e. I know the > trigger, but I can't work out why that trigger is now generating log > entries when it wasn't doing that before I installed and removed > auditd). > I'm guessing the removal scri

iptables changes triggering audit messages, despite auditd not being installed

2016-05-05 Thread Tony Evans
Debian 7.10 I recently installed auditd very briefly, to test something for a StackExchange question. It was installed for less than a couple of minutes, I create a single audit rule to watch a directory, and then uninstalled it. After it was uninstalled, I've been getting the following entries