Linux auditd Command
auditd is the audit daemon on Linux systems and is the core component of the Linux audit framework. Its main functions include monitoring and recording system activities, including:
- File and directory access
- System calls
- User login/logout
- Privileged command execution
- System configuration changes
These audit logs are very important for system security monitoring, compliance checks, and troubleshooting.
auditd Core Components
auditd Daemon
A continuously running daemon responsible for collecting and storing audit events.
auditctl Tool
A command-line tool used to configure audit rules and control the audit system.
ausearch Tool
A command-line tool used to query audit logs.
aureport Tool
Generates summary reports of audit logs.
auditd Installation and Startup
Install auditd
On most Linux distributions, auditd is usually preinstalled. If manual installation is needed:
Example
sudo apt-get install auditd
# CentOS/RHEL
sudo yum install audit
Start and Enable auditd Service
Example
sudo systemctl start auditd
# Enable startup on boot
sudo systemctl enable auditd
# Check service status
sudo systemctl status auditd
auditd Configuration File
The main configuration file for auditd is located at/etc/audit/auditd.confand contains the following important parameters:
| Parameter | Description | Default Value |
|---|---|---|
log_file |
Audit log file path | /var/log/audit/audit.log |
max_log_file |
Maximum size of a single log file (MB) | 8 |
num_logs |
Number of log files to retain | 5 |
flush |
Log write mode | INCREMENTAL |
freq |
How often to sync if flush=INCREMENTAL | 20 |
After modifying the configuration, restart the service:
sudo systemctl restart auditd
auditctl Command Details
auditctlis the main tool for configuring audit rules.
Basic Syntax
auditctl [选项] [规则]
Common Options
| Option | Description |
|---|---|
-l |
List all current rules |
-D |
Delete all rules |
-s |
Display audit system status |
-R <file> |
Load rules from a file |
Rule Types
File System Rules: Monitor file/directory access
Example
auditctl -w /etc/passwd -p rwxa -k passwd_access
-w: Monitor path-p: Permissions (r=read, w=write, x=execute, a=attribute change)-k: Key (for log filtering)
System Call Rules: Monitor specific system calls
Example
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k sudo_cmds
-a: Action and list (always,exit records when exiting a system call)-F: Filter conditions-S: System call name
User Rules: Monitor specific user behavior
Example
auditctl -a always,exit -S unlink -S unlinkat -S rename -S renameat -F auid>=500 -F auid!=4294967295 -k delete_files
Audit Log Analysis
ausearch Command
Used to query audit logs.
Example
ausearch -k passwd_access
# Search logs by specific time
ausearch -ts today
ausearch -ts 10:00:00 -te 11:00:00
# Search logs by specific user
ausearch -ua 1000
aureport Command
Generates summary reports of audit logs.
Example
aureport -l
# Generate file access report
aureport -f
# Generate summary report of all events
aureport --summary
Practical Application Examples
Example 1: Monitor Sensitive Files
Example
auditctl -w /etc/shadow -p wa -k shadow_mod
# View related logs
ausearch -k shadow_mod | less
Example 2: Monitor User Privilege Escalation
Example
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k priv_esc
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k priv_esc
# Generate privilege escalation report
aureport --start today --event --summary -i | grep priv_esc
Example 3: Monitor SSH Login
Example
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/sshd -k sshd_login
# View SSH login records
ausearch -k sshd_login | grep 'acct="user"' | grep 'res=success'
Best Practices
Set up log rotation properly: Ensure logs don't fill up the disk
Example
max_log_file = 50
num_logs = 10
Centrally manage audit rules: Save rules in a file
Example
-w /etc/passwd -p wa -k passwd_changes
-w /etc/group -p wa -k group_changes
# Load rules
auditctl -R /etc/audit/rules.d/my.rules
Review logs regularly: Set up a cron job to analyze logs regularly
Example
0 0 * * * /usr/sbin/aureport --summary --start yesterday --end now | mail -s "Daily Audit Report" admin@example.com
Protect audit logs: Prevent logs from being tampered with
Example
chown root:root /var/log/audit/audit.log
Troubleshooting Common Issues
Issue 1: auditd Service Fails to Start
Solution:
- Check configuration file syntax:
auditd -f /etc/audit/auditd.conf - Check system logs:
journalctl -u auditd
Issue 2: No Audit Logs Generated
Solution:
- Confirm the service is running:
systemctl status auditd - Check whether rules are loaded:
auditctl -l - Verify kernel support:
grep "audit" /boot/config-$(uname -r)
Issue 3: Log Files Too Large
Solution:
- Adjust log size and quantity: modify
/etc/audit/auditd.confinmax_log_fileandnum_logs - Enable log compression: add
compress = yesto the configuration file
Summary
auditd is a powerful auditing tool for Linux systems. With proper configuration, you can:
- Monitor access to critical files and directories
- Track usage of privileged commands
- Record user logins and system activities
- Meet compliance requirements
Mastering auditd is essential for system administrators and security professionals; it helps you better understand and protect your Linux system.
Other Extensions
Linux Command Encyclopedia