Thursday, January 26, 2012

audit logs reporting on Linux

I just found out about this command today, and it is pretty sweet!

$ aureport --avc


========================================================
# date time comm subj syscall class permission obj event
========================================================
1. 11/02/2011 15:40:55 nacl_helper_boo unconfined_u:unconfined_r:chrome_sandbox_t:s0-s0:c0.c1023 59 memprotect mmap_zero unconfined_u:unconfined_r:chrome_sandbox_t:s0-s0:c0.c1023 denied 6001
2. 11/03/2011 11:10:39 nacl_helper_boo unconfined_u:unconfined_r:chrome_sandbox_t:s0-s0:c0.c1023 59 memprotect mmap_zero unconfined_u:unconfined_r:chrome_sandbox_t:s0-s0:c0.c1023 denied 6237

The man pages has more information on the command.

0 comments: