12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Writing Audit Rules and Watches 511-S Specify a system call by name or number. To specify all system calls, use all asthe system call name. Start an audit record if a program uses this system call.Multiple system calls can be specified for the same rule, and each one must startwith -S. Specifying multiple system calls in the same rule instead of listing separaterules will result in better performance because only one rule has to be evaluated.-F Specify a rule field. If multiple fields are specified for a rule, all fields must be trueto start an audit record. Each rule must start with -F, and up to 64 rules may bespecified. If usernames and group names are used as fields instead of UIDs andGIDs, they are resolved to UIDs and GIDs for the matching. The following arevalid field names:pidProcess ID.ppiduideuidsuidfsuidgidegidsgidfsgidauidProcess ID of the parent process.User ID.Effective user ID.Set user ID.Filesystem user ID.Group ID.Effective group ID.Set group ID.Filesystem group ID.Audit ID, or the original ID the user logged in with.25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!