adutictl -F exe

Steve Grubb sgrubb at redhat.com
Wed Jan 11 13:57:24 UTC 2017


On Tuesday, January 10, 2017 3:49:16 PM EST Maupertuis Philippe wrote:
> Hello list,
> On my fedora 24 with audit-2.6.7-1.fc24.x86_64, the man auditctl list :
>               exe         Absolute path to application that while executing
> this rule will apply to. This can only be used on the exit list.
> 
> On my RHEL7.3 with audit-2.6.5-3.el7.x86_64 the option is missing.

I think the man page has it missing, but its there.

> Reading the changelog at https://people.redhat.com/sgrubb/audit/ChangeLog, I
> couldn't find in which version it was introduced.

2.5 - audit by process name

> Is this option available
> on 4.x kernel only ?

It was backported into the RHEL 7.3 kernel.

> Is there any chance that the option  finally arrive on RHEL 7 ?

Its there.

-Steve

> !!!*************************************************************************
> ************ "Ce message et les pi?ces jointes sont confidentiels et
> r?serv?s ? l'usage exclusif de ses destinataires. Il peut ?galement ?tre
> prot?g? par le secret professionnel. Si vous recevez ce message par erreur,
> merci d'en avertir imm?diatement l'exp?diteur et de le d?truire.
> L'int?grit? du message ne pouvant ?tre assur?e sur Internet, la
> responsabilit? de Worldline ne pourra ?tre recherch?e quant au contenu de
> ce message. Bien que les meilleurs efforts soient faits pour maintenir
> cette transmission exempte de tout virus, l'exp?diteur ne donne aucune
> garantie ? cet ?gard et sa responsabilit? ne saurait ?tre recherch?e pour
> tout dommage r?sultant d'un virus transmis.
> 
> This e-mail and the documents attached are confidential and intended solely
> for the addressee; it may also be privileged. If you receive this e-mail in
> error, please notify the sender immediately and destroy it. As its
> integrity cannot be secured on the Internet, the Worldline liability cannot
> be triggered for the message content. Although the sender endeavours to
> maintain a computer virus-free network, the sender does not warrant that
> this transmission is virus-free and will not be liable for any damages
> resulting from any virus transmitted.!!!"





More information about the Linux-audit mailing list