Linux auditd Command

Linux 命令大全Linux Command Encyclopedia


auditd is the audit daemon on Linux systems and is the core component of the Linux audit framework. Its main functions include monitoring and recording system activities, including:

  • File and directory access
  • System calls
  • User login/logout
  • Privileged command execution
  • System configuration changes

These audit logs are very important for system security monitoring, compliance checks, and troubleshooting.


auditd Core Components

auditd Daemon

A continuously running daemon responsible for collecting and storing audit events.

auditctl Tool

A command-line tool used to configure audit rules and control the audit system.

ausearch Tool

A command-line tool used to query audit logs.

aureport Tool

Generates summary reports of audit logs.


auditd Installation and Startup

Install auditd

On most Linux distributions, auditd is usually preinstalled. If manual installation is needed:

Example

# Ubuntu/Debian
sudo apt-get install auditd

# CentOS/RHEL
sudo yum install audit

Start and Enable auditd Service

Example

# Start the service
sudo systemctl start auditd

# Enable startup on boot
sudo systemctl enable auditd

# Check service status
sudo systemctl status auditd

auditd Configuration File

The main configuration file for auditd is located at/etc/audit/auditd.confand contains the following important parameters:

Parameter Description Default Value
log_file Audit log file path /var/log/audit/audit.log
max_log_file Maximum size of a single log file (MB) 8
num_logs Number of log files to retain 5
flush Log write mode INCREMENTAL
freq How often to sync if flush=INCREMENTAL 20

After modifying the configuration, restart the service:

sudo systemctl restart auditd

auditctl Command Details

auditctlis the main tool for configuring audit rules.

Basic Syntax

auditctl [选项] [规则]

Common Options

Option Description
-l List all current rules
-D Delete all rules
-s Display audit system status
-R <file> Load rules from a file

Rule Types

File System Rules: Monitor file/directory access

Example

# Monitor read, write, and attribute changes to /etc/passwd
auditctl -w /etc/passwd -p rwxa -k passwd_access
  • -w: Monitor path
  • -p: Permissions (r=read, w=write, x=execute, a=attribute change)
  • -k: Key (for log filtering)

System Call Rules: Monitor specific system calls

Example

# Monitor all commands using sudo
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k sudo_cmds
  • -a: Action and list (always,exit records when exiting a system call)
  • -F: Filter conditions
  • -S: System call name

User Rules: Monitor specific user behavior

Example

# Monitor file deletion by users with UID greater than 500
auditctl -a always,exit -S unlink -S unlinkat -S rename -S renameat -F auid&gt;=500 -F auid!=4294967295 -k delete_files

Audit Log Analysis

ausearch Command

Used to query audit logs.

Example

# Search logs by specific keyword
ausearch -k passwd_access

# Search logs by specific time
ausearch -ts today
ausearch -ts 10:00:00 -te 11:00:00

# Search logs by specific user
ausearch -ua 1000

aureport Command

Generates summary reports of audit logs.

Example

# Generate user login report
aureport -l

# Generate file access report
aureport -f

# Generate summary report of all events
aureport --summary

Practical Application Examples

Example 1: Monitor Sensitive Files

Example

# Monitor /etc/shadow file
auditctl -w /etc/shadow -p wa -k shadow_mod

# View related logs
ausearch -k shadow_mod | less

Example 2: Monitor User Privilege Escalation

Example

# Monitor all commands using sudo or su
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k priv_esc
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k priv_esc

# Generate privilege escalation report
aureport --start today --event --summary -i | grep priv_esc

Example 3: Monitor SSH Login

Example

# Monitor SSH login success and failure
auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/sshd -k sshd_login

# View SSH login records
ausearch -k sshd_login | grep 'acct="user"' | grep 'res=success'

Best Practices

Set up log rotation properly: Ensure logs don't fill up the disk

Example

# Edit /etc/audit/auditd.conf
max_log_file = 50
num_logs = 10

Centrally manage audit rules: Save rules in a file

Example

# Create rules file /etc/audit/rules.d/my.rules
-w /etc/passwd -p wa -k passwd_changes
-w /etc/group -p wa -k group_changes

# Load rules
auditctl -R /etc/audit/rules.d/my.rules

Review logs regularly: Set up a cron job to analyze logs regularly

Example

# Generate a report daily and send it to the administrator
0 0 * * * /usr/sbin/aureport --summary --start yesterday --end now | mail -s "Daily Audit Report" admin@example.com

Protect audit logs: Prevent logs from being tampered with

Example

chmod 600 /var/log/audit/audit.log
chown root:root /var/log/audit/audit.log

Troubleshooting Common Issues

Issue 1: auditd Service Fails to Start

Solution:

  1. Check configuration file syntax:auditd -f /etc/audit/auditd.conf
  2. Check system logs:journalctl -u auditd

Issue 2: No Audit Logs Generated

Solution:

  1. Confirm the service is running:systemctl status auditd
  2. Check whether rules are loaded:auditctl -l
  3. Verify kernel support:grep "audit" /boot/config-$(uname -r)

Issue 3: Log Files Too Large

Solution:

  1. Adjust log size and quantity: modify/etc/audit/auditd.confinmax_log_fileandnum_logs
  2. Enable log compression: addcompress = yesto the configuration file

Summary

auditd is a powerful auditing tool for Linux systems. With proper configuration, you can:

  • Monitor access to critical files and directories
  • Track usage of privileged commands
  • Record user logins and system activities
  • Meet compliance requirements

Mastering auditd is essential for system administrators and security professionals; it helps you better understand and protect your Linux system.


Linux 命令大全Linux Command Encyclopedia

Other Extensions