Mondoo Docs

auditd (Linux Audit Daemon) rule for a file

eg: -w /etc/shadow -p rw -k shadow_access => (path: "/etc/shadow", permissions: "rw", keyname: "shadow_access")

Operating SystemPrivate Resource

auditd (Linux Audit Daemon) rule for a file

eg: -w /etc/shadow -p rw -k shadow_access => {path: "/etc/shadow", permissions: "rw", keyname: "shadow_access"}

Min version: 9.0.0Defaults: path permissions

Relationships

Mini Map
Operating System
3 resources · 2 relationshipsClick to select, expand fields to see properties.

Fields (3)

FieldTypeDescription
keynamerequired
stringthe key name for related rules as specified by -k
pathrequired
stringthe path this rule matches as specified by -w
permissionsrequired
stringthe permissions specified by this rule via -p