[PATCH ghak28/ghak25 user 0/2] parse EVENT_LISTENER and NETFILTER_CFG
Richard Guy Briggs
rgb at redhat.com
Tue May 19 15:31:25 UTC 2020
Add a parser to parse subject attributes from EVENT_LISTENER and
NETFILTER_CFG record types.
This is a new order for subject attributes for two record types that
usually occur in user context and therefore would be informed by a
SYSCALL record, but occasionally stand alone and need the subject
attributes added. In the case of the NETFILTER_CFG event, since it is
kernel-initiated, several of the subject attributes are unset and
meaningless in the kernel context and duplicates in user context, hence
removed.
Please see the upstream issues
https://github.com/linux-audit/audit-kernel/issues/28 and
https://github.com/linux-audit/audit-kernel/issues/25 .
Richard Guy Briggs (2):
ausearch-parse: add parser for YAASAO
ausearch-parse: mod parser for YAASAO for NETFILTER_CFG
src/ausearch-parse.c | 170 ++++++++++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 169 insertions(+), 1 deletion(-)
--
1.8.3.1
More information about the Linux-audit
mailing list