Source between audit and Syslog

Source: Internet
Author: User

Purpose of audit:

Records events at the core layer, reads and writes files, and calls from the system. Permission status

Belongs to the kernel

Syslog purpose:

Belongs to the application layer and records all application-layer error messages.


Audit has three operating tools


Three commands available for audit:


=> Auditctl-controls the kernel audit system, which can be used to retrieve, add, or delete rules, and set the watch for a specific case ).


=> Ausearch-the tool used to check the Audit audit logs.


=> Aureport-generate the audit system crash tool.


4. Set hosts


Audit is set to/etc/audit. Rules, which is divided into three types:


? Basic Audit System Parameters

? File and directory watches

? System Call audits







Source between audit and Syslog

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.