cancel
Showing results for 
Search instead for 
Did you mean: 
Trevor
Starfighter Starfighter
Starfighter
  • 117 Views

Auditd Record Type

Each event recorded by auditd, has a record type associated with it.

What record type is triggered by the auditd daemon, when an 
SELinux boolean value is changed?

 

 

Trevor "Red Hat Evangelist" Chandler
Labels (3)
1 Reply
TM
Flight Engineer Flight Engineer
Flight Engineer
  • 81 Views

Launching the below in one terminal
tail -f /var/log/audit/audit.log | grep httpd_use_nfs

And the below in an other
setsebool httpd_use_nfs=on

I see in the first terminal
type=MAC_CONFIG_CHANGE msg=audit(1730101288.652:110): bool=httpd_use_nfs val=1 old_val=0 auid=0 ses=1AUID="root"

So the type of audit log while changing an SE Linux boolean is MAC_CONFIG_CHANGE.

 

Join the discussion
You must log in to join this conversation.