SF.net SVN: logwatch:[249] trunk

[email protected] Thu, 25 Sep 2014 16:12:37 +0000
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
Revision: 249
          http://sourceforge.net/p/logwatch/code/249
Author:   opoplawski
Date:     2014-09-25 16:12:36 +0000 (Thu, 25 Sep 2014)
Log Message:
-----------
[audit] Do not strip the audit service so we can better parse the different audit services messages

Modified Paths:
--------------
    trunk/conf/services/audit.conf
    trunk/scripts/services/audit

Modified: trunk/conf/services/audit.conf
===================================================================
--- trunk/conf/services/audit.conf	2014-09-24 15:48:24 UTC (rev 248)
+++ trunk/conf/services/audit.conf	2014-09-25 16:12:36 UTC (rev 249)
@@ -22,7 +22,8 @@
 # as the service name
 # (Some implementations might not precede it with "kernel:")
 *OnlyService = (kernel:( \[[ 0-9\.]+\])?)?\s*(type=[0-9]+\s*)?audit.*
-*RemoveHeaders
+# Need to distinguish between the various audit services
+*RemoveHeaders = "^... .. ..:..:.. [^ ]* (?:kernel: )?"
 
 ########################################################
 # This was written and is maintained by:

Modified: trunk/scripts/services/audit
===================================================================
--- trunk/scripts/services/audit	2014-09-24 15:48:24 UTC (rev 248)
+++ trunk/scripts/services/audit	2014-09-25 16:12:36 UTC (rev 249)
@@ -131,7 +131,7 @@
         ( $ThisLine =~ /type=[0-9]+ audit\([0-9.]*:[0-9]*\): user/) or
         ( $ThisLine =~ /audit_printk_skb: [0-9]* callbacks suppressed/) or
 	( $ThisLine =~ /item=[0-9] name="\S*" inode=[0-9]+ dev=\S* mode=[0-9]* ouid=[0-9]* ogid=[0-9]* rdev=[0-9:]* obj=\S*/) or
-	( $ThisLine =~ /^No rules$/ )
+	( $ThisLine =~ /^auditctl: No rules$/ )
     ) {
 	# Ignore these entries
     } elsif ( $ThisLine =~ /audit\([0-9]{10}.[0-9]{3}:[0-9]\): initialized$/) {
@@ -158,6 +158,8 @@
       $Warning{$ThisLine}++;
     } elsif ( my ($status) = ( $ThisLine =~ /AUDIT_STATUS: (.*)/ ) ) {
       $AuditctlStatus{$status}++; 
+    } elsif ( my ($status) = ( $ThisLine =~ /^auditctl: (.*)/ ) ) {
+      $AuditctlStatus{$status}++; 
     } elsif ( $ThisLine =~ /audit\([0-9]+\.[0-9]+:[0-9]+\): apparmor=/) {
         # AppArmor
         if ( $ThisLine =~ /apparmor="STATUS" operation="profile_(load|replace)" name="([^"]+)"/ ) {

This was sent by the SourceForge.net collaborative development platform, the world's largest Open Source development site.


------------------------------------------------------------------------------
Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer
Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports
Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper
Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer
http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk