Re: auditd log processing tools?

2021-01-29 Thread Tim via users
sixpack13 wrote: >> to me it seems completely unnecessary. >> My comment is right under the comment I replied to. Ed Greshko: > You may think it is unnecessary. However, some people have their > email clients configured to display "unread" messages. When a reply > is sent sometime after the ori

Re: auditd log processing tools?

2021-01-29 Thread Ed Greshko
On 30/01/2021 07:05, sixpack13 wrote: On Fri, 2021-01-29 at 21:59 +, sixpack13 wrote: And once again, you didn't quote what you are replying to. poc to me it seems completely unnecessary. My comment is right under the comment I replied to. You may think it is unnecessary.  However, so

Re: auditd log processing tools?

2021-01-29 Thread Patrick O'Callaghan
On Fri, 2021-01-29 at 23:05 +, sixpack13 wrote: > > On Fri, 2021-01-29 at 21:59 +, sixpack13 wrote: > > > > And once again, you didn't quote what you are replying to. > > > > poc > > to me it seems completely unnecessary. > My comment is right under the comment I replied to. > > tha

Re: auditd log processing tools?

2021-01-29 Thread sixpack13
s/provides/provided/ ___ users mailing list -- users@lists.fedoraproject.org To unsubscribe send an email to users-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https:

Re: auditd log processing tools?

2021-01-29 Thread sixpack13
> On Fri, 2021-01-29 at 21:59 +, sixpack13 wrote: > > And once again, you didn't quote what you are replying to. > > poc to me it seems completely unnecessary. My comment is right under the comment I replied to. that is the case now here in hyperkitty and - IIRC- was the same when I read

Re: auditd log processing tools?

2021-01-29 Thread Patrick O'Callaghan
On Fri, 2021-01-29 at 21:59 +, sixpack13 wrote: > Aha ! > THX, something learned And once again, you didn't quote what you are replying to. poc ___ users mailing list -- users@lists.fedoraproject.org To unsubscribe send an email to users-le...@lis

Re: auditd log processing tools?

2021-01-29 Thread sixpack13
@Alex obviously I provides wrong info's trying to answer your questions. sorry ! ___ users mailing list -- users@lists.fedoraproject.org To unsubscribe send an email to users-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraprojec

Re: auditd log processing tools?

2021-01-29 Thread sixpack13
Aha ! THX, something learned ___ users mailing list -- users@lists.fedoraproject.org To unsubscribe send an email to users-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines

Re: auditd log processing tools?

2021-01-29 Thread Samuel Sieb
On 1/29/21 1:19 PM, sixpack13 wrote: in the OP's text: - 1. sentence, last part: "...would like to get more involved with auditd." - in the 2. sentence, 2. part: "..., but are there any tools to process the audit.log..." - in the 4. paragraph, last part of the se

Re: auditd log processing tools?

2021-01-29 Thread sixpack13
in the OP's text: - 1. sentence, last part: "...would like to get more involved with auditd." - in the 2. sentence, 2. part: "..., but are there any tools to process the audit.log..." - in the 4. paragraph, last part of the sentence: "..., but what do p

Re: auditd log processing tools?

2021-01-29 Thread Patrick O'Callaghan
On Fri, 2021-01-29 at 12:08 -0500, Garry T. Williams wrote: > On Friday, January 29, 2021 9:47:35 AM EST Greg Woods wrote: > > I have personal experience with Gmail, where I used to be able > > to highlight part of the message, and that was all that would be included > > in my reply, but that no lo

Re: auditd log processing tools?

2021-01-29 Thread Garry T. Williams
On Friday, January 29, 2021 9:47:35 AM EST Greg Woods wrote: > I have personal experience with Gmail, where I used to be able > to highlight part of the message, and that was all that would be included > in my reply, but that no longer works; the entire message is included and I > have to manually

Re: auditd log processing tools?

2021-01-29 Thread Patrick O'Callaghan
On Fri, 2021-01-29 at 07:47 -0700, Greg Woods wrote: > I have personal experience with Gmail, where I used to be able > to highlight part of the message, and that was all that would be > included > in my reply, but that no longer works; the entire message is included > and I > have to manually trim

Re: auditd log processing tools?

2021-01-29 Thread George N. White III
On Fri, 29 Jan 2021 at 06:31, Patrick O'Callaghan wrote: > On Fri, 2021-01-29 at 17:59 +1030, Tim via users wrote: > > On Thu, 2021-01-28 at 16:49 -0800, Samuel Sieb wrote: [...] > > Or, put another way, there's a very good reason why the long- > > established way to participate in a mailing lis

Re: auditd log processing tools?

2021-01-29 Thread Greg Woods
On Fri, Jan 29, 2021 at 3:32 AM Patrick O'Callaghan wrote: > > there's a very good reason why the long- > > established way to participate in a mailing list is quote the salient > > bits of the prior email and directly reply to individual sentences or > > paragraphs right underneath them. So tha

Re: auditd log processing tools?

2021-01-29 Thread Patrick O'Callaghan
On Fri, 2021-01-29 at 17:59 +1030, Tim via users wrote: > On Thu, 2021-01-28 at 16:49 -0800, Samuel Sieb wrote: > > You completely removed any context and your message is unclear... > > Q: How many surrealists does it take to change a light bulb? > > A: Two, one to hold the giraffe, and the other

Re: auditd log processing tools?

2021-01-28 Thread Tim via users
On Thu, 2021-01-28 at 16:49 -0800, Samuel Sieb wrote: > You completely removed any context and your message is unclear... Q: How many surrealists does it take to change a light bulb? A: Two, one to hold the giraffe, and the other to fill the bathtub with brightly colored machine tools. Or, put

Re: auditd log processing tools?

2021-01-28 Thread Samuel Sieb
unclear... selinux and auditd are separate, so I have no idea what you're trying to say here. ___ users mailing list -- users@lists.fedoraproject.org To unsubscribe send an email to users-le...@lists.fedoraproject.org Fedora Code of Conduct:

Re: auditd log processing tools?

2021-01-28 Thread sixpack13
could sudo dnf install setroubleshoot-server setroubleshoot and/or https://docs.fedoraproject.org//en-US/Fedora/25/html/SELinux_Users_and_Administrators_Guide/index.html - actuality ??? - help ? ___ users mailing list -- users@lists.fedoraproject.org T

auditd log processing tools?

2021-01-27 Thread Alex
Hi, I have a fedora33 system and would like to get more involved with auditd. I understand the basics, but are there any tools to process the audit.log file, to make it easier to process, read and display? How about acting on specific events? What if I wanted to be alerted somehow when sudo was

Re: Silencing auditd in fedora22

2015-07-19 Thread Alex Regan
Hi, Since upgrading from fedora22, auditd is drowning /var/log/messages with useless information such as this: Jul 18 19:02:19 orion audit: pid=6002 uid=0 auid=4294967295 ses=4294967295 msg='op=destroy kind=server fp=SHA256:b5:7b:76:df:38:16:f3:f5:cd:2f:67:54:9a:2e:68:15:ae:9c:40:50:4f:

Re: Silencing auditd in fedora22

2015-07-19 Thread Alex Regan
Hi, Since upgrading from fedora22, auditd is drowning /var/log/messages with useless information such as this: Jul 18 19:02:19 orion audit: pid=6002 uid=0 auid=4294967295 ses=4294967295 msg='op=destroy kind=server fp=SHA256:b5:7b:76:df:38:16:f3:f5:cd:2f:67:54:9a:2e:68:15:ae:9c:40:50:4f:

Re: Silencing auditd in fedora22

2015-07-19 Thread Bill Shirley
On 7/18/2015 7:08 PM, Alex wrote: Hi, Since upgrading from fedora22, auditd is drowning /var/log/messages with useless information such as this: Jul 18 19:02:19 orion audit: pid=6002 uid=0 auid=4294967295 ses=4294967295 msg='op=destroy kind=server fp=SHA256:b5:7b:76:df:38:16:f3:f5:cd:

Re: Silencing auditd in fedora22

2015-07-18 Thread dwoody5654
On 07/18/2015 06:08 PM, Alex wrote: Hi, Since upgrading from fedora22, auditd is drowning /var/log/messages with useless information such as this: Jul 18 19:02:19 orion audit: pid=6002 uid=0 auid=4294967295 ses=4294967295 msg='op=destroy kind=server fp=SHA256:b5:7b:76:df:38:16:f3:f5:cd:

Re: Silencing auditd in fedora22

2015-07-18 Thread Tom Horsley
On Sat, 18 Jul 2015 19:08:20 -0400 Alex wrote: > I've enabled rsyslog because the logs are so much easier to access, > but I'm not using auditd so would like to just turn it off. stick audit=0 on the kernel command line options in grub.cfg, disable the auditd service (or unins

Silencing auditd in fedora22

2015-07-18 Thread Alex
Hi, Since upgrading from fedora22, auditd is drowning /var/log/messages with useless information such as this: Jul 18 19:02:19 orion audit: pid=6002 uid=0 auid=4294967295 ses=4294967295 msg='op=destroy kind=server fp=SHA256:b5:7b:76:df:38:16:f3:f5:cd:2f:67:54:9a:2e:68:15:ae:9c:40:50:4f:6d:

Re: Disabling auditd on Fedora 22

2015-06-23 Thread Daniel J Walsh
On 06/23/2015 12:36 AM, Kevin Wilson wrote: > Dan, > Thanks a lot for your reply. > In fact, I ran > pm -e selinux-policy-targeted > rpm -e selinux-policy > And after reboot I got some message about freeze from systemd, I could > not login (tried twice), so I reinstalled Linux on this machine. >

Re: Disabling auditd on Fedora 22

2015-06-22 Thread Martin Cigorraga
Hi, One of the reasons I'm using Fedora is because the exceptional support for SELinux and auditd that so far - despite a known incompatibility with Docker + Btrfs - is working great. Said that, kudos to everyone who makes SELinux integration such smooth. On Tue, Jun 23, 2015 at 1:36 AM

Re: Disabling auditd on Fedora 22

2015-06-22 Thread Kevin Wilson
Dan, Thanks a lot for your reply. In fact, I ran pm -e selinux-policy-targeted rpm -e selinux-policy And after reboot I got some message about freeze from systemd, I could not login (tried twice), so I reinstalled Linux on this machine. The question is: what do you mean by "If you disable SELinux".

Re: Disabling auditd on Fedora 22

2015-06-22 Thread Suvayu Ali
Hi Daniel, On 22 June 2015 at 15:41, Daniel J Walsh wrote: > On 06/22/2015 03:44 AM, Suvayu Ali wrote: >> On Mon, Jun 22, 2015 at 08:01:41AM +0300, Kevin Wilson wrote: >>> In /etc/selinux/config >>> >>> I set >>> SELINUX=disabled >>> Which means that I do not use in fact SElinux, so it seems to m

Re: Disabling auditd on Fedora 22

2015-06-22 Thread Daniel J Walsh
On 06/22/2015 03:44 AM, Suvayu Ali wrote: > On Mon, Jun 22, 2015 at 08:01:41AM +0300, Kevin Wilson wrote: >> In /etc/selinux/config >> >> I set >> SELINUX=disabled >> Which means that I do not use in fact SElinux, so it seems to me. > It is recommended to keep it permissive instead of disabled. >

Re: Disabling auditd on Fedora 22

2015-06-22 Thread Suvayu Ali
On Mon, Jun 22, 2015 at 08:01:41AM +0300, Kevin Wilson wrote: > > In /etc/selinux/config > > I set > SELINUX=disabled > Which means that I do not use in fact SElinux, so it seems to me. It is recommended to keep it permissive instead of disabled. > So will it be OK to run: > rpm -e selinux-poli

Re: Disabling auditd on Fedora 22

2015-06-21 Thread Kevin Wilson
, Ranjan Maitra wrote: > On Fri, 19 Jun 2015 19:19:15 -0400 Tom Horsley wrote: > >> On Fri, 19 Jun 2015 19:14:56 -0400 >> Sam Varshavchik wrote: >> >> > My totally unscientific assessment of auditd is that it's a massive syslog >> > spammer, and won'

Re: Disabling auditd on Fedora 22

2015-06-19 Thread Ranjan Maitra
On Fri, 19 Jun 2015 19:19:15 -0400 Tom Horsley wrote: > On Fri, 19 Jun 2015 19:14:56 -0400 > Sam Varshavchik wrote: > > > My totally unscientific assessment of auditd is that it's a massive syslog > > spammer, and won't be missed. > > There are a few o

Re: Disabling auditd on Fedora 22

2015-06-19 Thread Tom Horsley
On Fri, 19 Jun 2015 19:14:56 -0400 Sam Varshavchik wrote: > My totally unscientific assessment of auditd is that it's a massive syslog > spammer, and won't be missed. There are a few obscure questions you can answer about your system using auditd, but it is almost impossible to

Re: Disabling auditd on Fedora 22

2015-06-19 Thread Sam Varshavchik
Kevin Wilson writes: Hi all, Will I miss something critical if I will disable auditd on Fedora 22 by "systemctl disable auditd" ? My totally unscientific assessment of auditd is that it's a massive syslog spammer, and won't be missed. pgp96k7vv5BE7.pgp Descri

Disabling auditd on Fedora 22

2015-06-19 Thread Kevin Wilson
Hi all, Will I miss something critical if I will disable auditd on Fedora 22 by "systemctl disable auditd" ? Regards, Kevin -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Fedo

Re: auditd

2015-05-31 Thread Patrick O'Callaghan
(as close to as SELinux gets) user-friendly > > > explanations. > > Of course the biggest downside to turning off auditd, and > > potentially other logging services, is that when error/problems > > exist you'll not be notified nor will you have a record of what > &

Re: auditd

2015-05-30 Thread jd1008
On 05/30/2015 06:51 PM, Ed Greshko wrote: On 05/30/15 10:40, Matthew Miller wrote: is pretty effective. Primary downside: if you have SELinux violations, you don't get (as close to as SELinux gets) user-friendly explanations. Of course the biggest downside to turning off auditd

Re: auditd

2015-05-30 Thread Ed Greshko
On 05/30/15 10:40, Matthew Miller wrote: > is pretty effective. Primary downside: if you have SELinux violations, > you don't get (as close to as SELinux gets) user-friendly explanations. Of course the biggest downside to turning off auditd, and potentially other logging services, i

Re: auditd

2015-05-30 Thread Ed Greshko
On 05/31/15 07:51, jd1008 wrote: > > > On 05/29/2015 08:40 PM, Ed Greshko wrote: >> On 05/30/15 10:19, jd1008 wrote: >>> How can we stop auditd ??? >>> >> 2 choices >> >> 1. add audit=0 to the kernel command line in grub menu >> &

Re: auditd

2015-05-30 Thread jd1008
On 05/29/2015 08:40 PM, Ed Greshko wrote: On 05/30/15 10:19, jd1008 wrote: How can we stop auditd ??? 2 choices 1. add audit=0 to the kernel command line in grub menu or 2. systemctl mask auditd.service reboot. You can't stop it manually in a running system due to the settings i

Re: auditd

2015-05-29 Thread jd1008
On 05/29/2015 08:40 PM, Ed Greshko wrote: systemctl mask auditd.service Thanx Ed. I prefer your solution to removing packages. -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Fedora Code

Re: auditd

2015-05-29 Thread Ed Greshko
On 05/30/15 10:40, Matthew Miller wrote: > On Fri, May 29, 2015 at 08:19:47PM -0600, jd1008 wrote: >> How can we stop auditd ??? > > sudo dnf remove audit > > is pretty effective. Primary downside: if you have SELinux violations, > you don't get (as close to a

Re: auditd

2015-05-29 Thread Tom Horsley
On Fri, 29 May 2015 20:19:47 -0600 jd1008 wrote: > How can we stop auditd ??? Put audit=0 on the kernel options in grub.cfg (and /etc/default/grub) and also systemctl disable auditd.service and for good measure to be absolutely sure systemctl mask auditd.service I think that is two be

Re: auditd

2015-05-29 Thread Ed Greshko
On 05/30/15 10:19, jd1008 wrote: > How can we stop auditd ??? > 2 choices 1. add audit=0 to the kernel command line in grub menu or 2. systemctl mask auditd.service reboot. You can't stop it manually in a running system due to the settings in the auditd.service file. -- I

Re: auditd

2015-05-29 Thread Matthew Miller
On Fri, May 29, 2015 at 08:19:47PM -0600, jd1008 wrote: > How can we stop auditd ??? sudo dnf remove audit is pretty effective. Primary downside: if you have SELinux violations, you don't get (as close to as SELinux gets) user-friendly explanations. -- Matthew Miller Fedora Projec

auditd

2015-05-29 Thread jd1008
How can we stop auditd ??? -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct Guidelines: http://fedoraproject.org/wiki

Re: auditd is afiled how to enable

2013-03-29 Thread Joe Zeff
On 03/29/2013 06:58 AM, Suvayu Ali wrote: That is a common typo for "failed" (the a and f are interchanged). I bet everyone has made a typo like that sometime in the past. Other such comon typos could be missing letters, interchanging characters and spaces at word boundaries, etc. *Snicker!*

Re: auditd is afiled how to enable

2013-03-29 Thread Ed Greshko
On 03/29/13 23:52, Tim wrote: > Allegedly, on or about 29 March 2013, Ed Greshko sent: >> From now on, at least during winter time, Im going to blame all >> spelling an grammar erros on the cat sitting on my chest every time I >> sit down at the computer > And this generates a strange mental pi

Re: auditd is afiled how to enable

2013-03-29 Thread Tim
Allegedly, on or about 29 March 2013, Ed Greshko sent: > From now on, at least during winter time, Im going to blame all > spelling an grammar erros on the cat sitting on my chest every time I > sit down at the computer And this generates a strange mental picture... ;-) Is it an anti-gravit

Re: auditd is afiled how to enable

2013-03-29 Thread Ed Greshko
On 03/29/13 22:42, Reindl Harald wrote: > it's a difference having a typo in the subject or in the content > especially if someone speaks about auditd in the subject and > sshd in the content A typo is a typo. You just didn't have enough context for you to be able to figure i

Re: auditd is afiled how to enable

2013-03-29 Thread Reindl Harald
Am 29.03.2013 15:31, schrieb Ed Greshko: > On 03/29/13 21:58, Suvayu Ali wrote: >> Hi Reindl, >> >> On Fri, Mar 29, 2013 at 02:28:27PM +0100, Reindl Harald wrote: >>> your subject "auditd is afiled how to enable" does not describe >>> your probl

Re: auditd is afiled how to enable

2013-03-29 Thread Ed Greshko
On 03/29/13 21:58, Suvayu Ali wrote: > Hi Reindl, > > On Fri, Mar 29, 2013 at 02:28:27PM +0100, Reindl Harald wrote: >> your subject "auditd is afiled how to enable" does not describe >> your problem, "afiled" is AFAIK not a known word, so please >>

Re: auditd is afiled how to enable

2013-03-29 Thread Suvayu Ali
Hi Reindl, On Fri, Mar 29, 2013 at 02:28:27PM +0100, Reindl Harald wrote: > > your subject "auditd is afiled how to enable" does not describe > your problem, "afiled" is AFAIK not a known word, so please > consider in the future to describe your problem, find a m

Re: auditd is afiled how to enable

2013-03-29 Thread Reindl Harald
0530; 33min ago > > Main PID: 10063 (code=exited, status=255) well, after get rid of top-posting "yum install openssh-server" and what has this to do with auditd at all? your subject "auditd is afiled how to enable" does not describe your problem, "afiled" i

Re: auditd is afiled how to enable

2013-03-29 Thread Frank Murphy
On Fri, 29 Mar 2013 18:26:13 +0530 Prashanth Kasula wrote: > [root@KM-WS151 /]# service sshd status > Redirecting to /bin/systemctl status sshd.service > sshd.service > Loaded: error (Reason: No such file or directory) > Active: failed since Fri, 29 Mar 2013 17:44:48 +0530; > 3

Re: auditd is afiled how to enable

2013-03-29 Thread Prashanth Kasula
, Mar 29, 2013 at 5:27 PM, Reindl Harald wrote: > > > Am 29.03.2013 12:45, schrieb Prashanth Kasula: > > For sshd service there is a problem in enabling auditd service.if any > one knows the process please let us know. > > STOP TO START EACH DAY MULTIPLE THREADS WITHOUT AN

Re: auditd is afiled how to enable

2013-03-29 Thread Michael Schwendt
On Fri, 29 Mar 2013 12:57:51 +0100, Reindl Harald wrote: > > > Am 29.03.2013 12:45, schrieb Prashanth Kasula: > > For sshd service there is a problem in enabling auditd service.if any one > > knows the process please let us know. > > STOP TO START EACH DAY M

Re: auditd is afiled how to enable

2013-03-29 Thread Frank Murphy
On Fri, 29 Mar 2013 12:57:51 +0100 Reindl Harald wrote: > > > Am 29.03.2013 12:45, schrieb Prashanth Kasula: > > For sshd service there is a problem in enabling auditd service.if > > any one knows the process please let us know. > * what is your input > * what

Re: auditd is afiled how to enable

2013-03-29 Thread Reindl Harald
Am 29.03.2013 12:45, schrieb Prashanth Kasula: > For sshd service there is a problem in enabling auditd service.if any one > knows the process please let us know. STOP TO START EACH DAY MULTIPLE THREADS WITHOUT ANY INFORMATIONS FOR THE SAME PROBLEM - LEARN TO PROVIDE INFORMATIONS! &qu

auditd is afiled how to enable

2013-03-29 Thread Prashanth Kasula
Hi all, For sshd service there is a problem in enabling auditd service.if any one knows the process please let us know. Thanks Prashanth -- users mailing list users@lists.fedoraproject.org To unsubscribe or change subscription options: https://admin.fedoraproject.org/mailman/listinfo/users