Mondoo Docs

auditd (Linux Audit Daemon) rules aggregated on disk

via /etc/audit/audit.rules by default

Operating System

auditd (Linux Audit Daemon) rules aggregated on disk

via /etc/audit/audit.rules by default

Use MQL in cnspec shell or policy:

auditd.rules
Min version: 9.0.0

Relationships

Mini Map
Operating System
5 resources · 4 relationshipsClick to select, expand fields to see properties.

Fields (4)

FieldTypeDescription
controls
[]auditd.rule.controlall controls for auditd
files
[]auditd.rule.fileall file rules
path
stringpath to folder to look up rules
syscalls
[]auditd.rule.syscallall syscall rules