Introducing The Components Of Linux Audit - Novell LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009 Manual

Hide thumbs Also See for LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009:
Table of Contents

Advertisement

30.1 Introducing the Components of
The following figure illustrates how the various components of audit interact with each
other:
Figure 30.1 Introducing the Components of Linux Audit
application
Straight arrows represent the data flow between components while dashed arrows rep-
resent lines of control between components.
auditd
The audit daemon is responsible for writing the audit messages to disk that were
generated through the audit kernel interface and triggered by application and system
activity. How the audit daemon is started is controlled by its configuration file,
/etc/sysconfig/auditd. How the audit system functions once it is started
is controlled by /etc/audit/auditd.conf. For more information about auditd
and its configuration, refer to
(page 339).
338
Security Guide
Linux Audit
auditd.conf
audit.rules
auditctl
auditd
audit
kernel
audispd
audit.log
autrace
Section 30.2, "Configuring the Audit Daemon"
aureport
ausearch

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise desktop 11

Table of Contents