Back to tutorials
Key takeaways
auditdis the user-space half of the Linux audit system: the kernel produces the records, and the daemon writes them to /var/log/audit/audit.log.- Rules are dropped into
/etc/audit/rules.d/but only take effect after asudo augenrules --load. - Two families of rules: file watches such as
-w /etc/shadow -p wa -k shadow_changes, and syscall rules such as-a always,exit -F arch=b64 -S execve -F auid=1001 -k user_commands. - The
-kkey is not decoration: it is what lets you pull the events back later withausearch -k <key>. ausearchdigs through raw events (-k,-sc,-sv,-ua) whileaureportproduces summaries (-lfor logins,-sfor an overview,-au -i --failedfor authentication failures). Volume and rotation are tuned in/etc/audit/auditd.conf.
What is auditd?
The Linux audit daemon (
The Linux audit daemon (
auditd) is the user-space component of the Linux auditing system. It is responsible for writing the audit records generated by the kernel to disk. It is the fundamental tool for tracking security-relevant events on your system.
Why Use auditd?
- Traceability: Know who did what, and when. Essential for forensic investigations.
- Compliance: Helps meet the requirements of many security standards (PCI-DSS, HIPAA, etc.).
- Intrusion detection: Enables the detection of abnormal activity, such as unauthorized access to critical files.
Prerequisites
- Operating system: Any modern Linux distribution.
- Privileges: Root access or sudo privileges.
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime