auditd (Linux Audit Daemon) rule for a syscall
eg: -a always,exit -F arch=b32 -F auid>=1000 -F auid!=unset => ( action: "always", list: "exit", syscalls: [], field_entries: [ key="arch" op="=" value="b32" key="auid" op=">=" value="1000" key="auid" op="!=" value="unset" ], keyname: nil, )
Operating SystemPrivate Resource
auditd (Linux Audit Daemon) rule for a syscall
eg: -a always,exit -F arch=b32 -F auid>=1000 -F auid!=unset => { action: "always", list: "exit", syscalls: [], field_entries: [ key="arch" op="=" value="b32" key="auid" op=">=" value="1000" key="auid" op="!=" value="unset" ], keyname: nil, }
Min version: 9.0.0Defaults:
action listRelationships
3 resources · 2 relationships·Click to select, expand fields to see properties.
Fields (5)
| Field | Type | Description |
|---|---|---|
actionrequired | string | the action specified by -a |
fieldsrequired | []dict | all field entries as raw values as specified by -F |
keynamerequired | string | the key name for related rules as specified by -k |
listrequired | string | the list, the second value specified by -a |
syscallsrequired | []string | the list of syscalls that this rule matches specified by -S |