Add in support for audisp-simplify
This summaries multiple lines of the audit log file nicely, but it is not clear if it will satisfy the auditor's since there is not connection to the original user for users that login using kerberos to gain root access to the system.
Showing
- files/etc/audisp/audispd.conf 1 addition, 1 deletionfiles/etc/audisp/audispd.conf
- files/etc/audisp/plugins.d/simplify.conf 5 additions, 0 deletionsfiles/etc/audisp/plugins.d/simplify.conf
- files/etc/audit/audit.rules 10 additions, 7 deletionsfiles/etc/audit/audit.rules
- files/etc/newsyslog.daily/audisp-simplify 10 additions, 0 deletionsfiles/etc/newsyslog.daily/audisp-simplify
- manifests/auditd.pp 19 additions, 2 deletionsmanifests/auditd.pp
Loading
Please register or sign in to comment