DId +cp /usr/share/doc/audit-2.8.4/rules/30-stig.rules stig.rules= to put these rules into /etc/audit/rules.d. Then restarted service using service auditd restart. For this command the systemctl mechanism is blocked for restart. However, some rules needed to be added (e.g., setuid and setgid monitoring).
Topic revision: r1 - 2019-07-31, JimJacobs
This site is powered by FoswikiCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding NRAO Public Wiki? Send feedback