suppress log entries, how?

Steve Grubb sgrubb at redhat.com
Wed Oct 1 13:55:03 UTC 2014


On Wednesday, October 01, 2014 08:46:18 AM Marko Weber | 8000 wrote:
> good morning list,
> 
> i installed auditd on my gentoo server.
> installation runs without error, but on start i get this:
> 
> # /etc/init.d/auditd start
>   * Starting auditd ...
> 
>                                                [ ok ]
> touch: cannot touch '/var/lock/subsys/auditd': No such file or directory
>   * Loading audit rules from /etc/audit/audit.rules
> 
> seems /var/lock/ `subsys/auditd` is missing.
> that was easy to fix, but has to be repeated after every reboot.
> 
> 
> in auditd.log i get entries like this:
> 
> type=NETFILTER_CFG msg=audit(1412022284.553:2446): table=mangle family=2
> entries=6
> type=SYSCALL msg=audit(1412022284.553:2446): arch=c000003e syscall=54
> success=yes exit=0 a0=4 a1=0 a2=40 a3=1144850 items=0 ppid=2070 pid=2130
> auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0
> tty=(none) ses=4294967295 comm="iptables" exe="/sbin/xtables-multi"
> key=(null)
> 
> i want to suppress these messages.
> in my understanding of the man page i have to put such a rule into
> audit.rules:
> 
> -a exclude,never -F msgtype=NETFILTER_CFG , but this isnt working. the
> messages still appears.

Note that this says "never exclude"  :-)  I think you want -a exclude,always. 
Give that a try.

-Steve




More information about the Linux-audit mailing list