Re: Exclude /usr/libexec/mysqld from audit.rules

2013-12-10 Thread Derek Warner
Steve, Thank you very much. I have corrected my audit.rules. :) Derek Warner – CISSP-ISSEP Information System Security Engineer Riptide Software w- 321-296-0068 x 136 c- 407-716-9223 derek.war...@riptidesoftware.com derek.a.war...@us.army.mil On Mon, Dec 9, 2013 at 11:22 AM, Steve

Re: Exclude /usr/libexec/mysqld from audit.rules

2013-12-09 Thread Derek Warner
Steve, Thanks again, I am really trying to get my linux skills sharpened as I have been unfortunately raised in the windows world. It does pay the bills though. V/R Derek Warner – CISSP-ISSEP Information System Security Engineer Riptide Software w- 321-296-0068 x 136 c- 407-716-9223

Re: Exclude /usr/libexec/mysqld from audit.rules

2013-12-09 Thread Derek Warner
I get it. Is this something that is identified for a fix in RHEL? Since RHEL ports the mysql would it be mysql that provides the fix or RHEL? V/R Derek Derek Warner – CISSP-ISSEP Information System Security Engineer Riptide Software w- 321-296-0068 x 136 c- 407-716-9223 derek.war

Re: Exclude /usr/libexec/mysqld from audit.rules

2013-12-09 Thread Derek Warner
mail chain. How did you "interpret" the log setting to retreive the syscall "sched_setparam"? Anyhow I am not sure why we want this, I have no idea what the sched_setparam actually does. Did you do a lookup on the mysql syscall number? Again, I always appreciate your assistance

Exclude /usr/libexec/mysqld from audit.rules

2013-12-09 Thread Derek Warner
sqld" key=(null) I have tried the following: -a exit,never -F path=/usr/libexec/mysqld When using "-F" I noticed in one RHEL forum someone used -F exe= However in CENTOS exe is not a recognized field when using -F We do not wish to audit this data, can someone please help me