It reads and automatically parses the Linux audit logs. You can override the file name using the filename() parameter and the prefix for the created name-value pairs using the prefix() parameter. Any additional parameters are passed to the file source.
Prerequisites
Install the axosyslog-scl package on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of the axosyslog base package.
Your configuration must also contain @include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an unexpected LL_IDENTIFIER error.
@include "scl.conf"Declaration
linux-audit(options);Example: Using the linux-audit() driver
source s_auditd {
linux-audit(
prefix("test.")
hook-commands(
startup("auditctl -w /etc/ -p wa")
shutdown("auditctl -W /etc/ -p wa")
)
);
};
linux-audit() source options
The linux-audit() driver has the following options:
filename()
| Type: | path |
| Default: |
Description: The log file of linux-audit. The AxoSyslog application reads the Linux audit logs from this file.
prefix()
| Synopsis: | prefix() |
| Default: | .auditd. |
Description: Insert a prefix before the name part of the parsed name-value pairs to help further processing. For example:
- To insert the
my-parsed-data.prefix, use theprefix(my-parsed-data.)option. - To refer to a particular data that has a prefix, use the prefix in the name of the macro, for example,
${my-parsed-data.name}. - If you forward the parsed messages using the IETF-syslog protocol, you can insert all the parsed data into the SDATA part of the message using the
prefix(.SDATA.my-parsed-data.)option.
Names starting with a dot (for example, .example) are reserved for use by AxoSyslog. Note that if you use an empty prefix (prefix("")) or one starting with a dot, AxoSyslog might replace the original value of an existing macro (note that only soft macros can be overwritten, see Hard versus soft macros for details). To avoid such problems, use a prefix when naming the parsed values, for example, prefix(my-parsed-data.)