Re: Comprehensive Documentation on the Linux Audit Framework

2023-06-06 Thread Richard Guy Briggs
On 2023-06-06 18:01, Paul Moore wrote: > On Tue, Jun 6, 2023 at 3:09 PM Steve Grubb wrote: > > On Tuesday, June 6, 2023 6:31:55 PM EDT Vincent Abraham wrote: > > > Thanks. Could you also point to portions in the codebase where these > > > functions are called for monitoring file access? > > > >

Re: Comprehensive Documentation on the Linux Audit Framework

2023-06-06 Thread Paul Moore
On Tue, Jun 6, 2023 at 3:09 PM Steve Grubb wrote: > On Tuesday, June 6, 2023 6:31:55 PM EDT Vincent Abraham wrote: > > Thanks. Could you also point to portions in the codebase where these > > functions are called for monitoring file access? > > I'll let Richard or Paul point to the place in the

Re: Comprehensive Documentation on the Linux Audit Framework

2023-06-06 Thread Steve Grubb
On Tuesday, June 6, 2023 6:31:55 PM EDT Vincent Abraham wrote: > Thanks. Could you also point to portions in the codebase where these > functions are called for monitoring file access? I'll let Richard or Paul point to the place in the kernel if that's necessary. I think there's a fundamental

Re: Comprehensive Documentation on the Linux Audit Framework

2023-06-06 Thread Vincent Abraham
Thanks. Could you also point to portions in the codebase where these functions are called for monitoring file access? The reason I'm asking for this is that I'm trying to provide auditing for files of a specific type and I'm trying to understand how would that work. Any help would be appreciated.