Hello Ad_astra,
Did you try your suggeston????
Hello Trevor
Sorry, I forgot to include the arch option. So, the full command should have been:
auditctl -a exit,always -F arch=b64 -S execve
Regards
Hi
There's not much activity on this thread, anymore. Please can we have a solution to this question?
Thanks
Red Hat
Learning Community
A collaborative learning environment, enabling open source skill development.