[Bug 1867372] Re: Auditd failed when changing the Rsyslog configuration

2020-03-16 Thread Dmitriy Kulikov
After many experiments, I discovered an inconspicuous syntax error in audit.rules Here are two seemingly identical lines: -a exit,always -F arch=b64 -F euid=0 -S execve –k root_actions -a exit,always -F arch=b64 -F euid=0 -S execve -k root_actions Their only difference is that in the first line

[Bug 1867372] [NEW] Auditd failed when changing the Rsyslog configuration

2020-03-13 Thread Dmitriy Kulikov
Public bug reported: I found that when changing the Rsyslog configuration (/etc/rsyslog.d/50-default.conf) an Auditd failure occurs with distinctive strings in syslog: ExecStartPost=/sbin/augenrules --load (code=exited, status=1/FAILURE) . There was an error in line 6 of