LINUX- 39 AUDIT (RHEL-7) P2
WHAT IS AUDIT AND IT’s
SIGNIFICANCE,
HOW TO CREATE/DELETE/EDIT/DISABLE/REMOVE AUDIT LOGS:
Apart
from default auditing we can configure the rules to direct auditd to keep watch
on particular file/action.
The
Audit system operates on a set of rules that define what is to be captured in
the log files. There are three types of Audit rules that can be specified: