The audit package contains the user-space utilities for creating audit rules, as well as for storing, searching, and generating reports from the audit records generated by the audit subsystem in the Linux 2.6 kernel and higher. It has a real-time plugin interface for event analysis and remote logging of events.
|Tags||Logging Security Monitoring|
|Licenses||GPLv2 or later|
|Operating Systems||Linux (32 and 64 bit) POSIX|
Release Notes: Improved ARM and AARCH64 support, a new checkpoint feature in ausearch, an update of aulast to support recent LOGIN events in recent kernels, plus various cleanups, bugfixes, and documentation improvements.
Release Notes: This release updates the syscall table for the 3.3 Linux kernel, fixes a bug in grouping records in the same event when the node name is too long, and adds a new feature to ausearch to interpret some arguments to over 40 common syscalls.
Release Notes: This release adds lots of bugfixes in ausearch parsing of event records, improvements to the sample rules, support for virtualization events, a new auvirt utility, and interfield comparison support for the 3.3 and later kernels.
Release Notes: The event parsers were reviewed and updated for better event analysis. A few daemon generated events were fixed. Reliability of remote event logging was improved.
Release Notes: Many improvements were made to the robustness of remote logging. Some problems related to audispd plugin management were fixed. autrace was fixed for the i386 and s390 platforms.