February 2020
Intermediate to advanced
666 pages
15h 45m
English
In the /usr/share/doc/audit-version_number/rules directory of your CentOS 7 machine and the /usr/share/doc/audit/rules directory of your CentOS 8 machine, you'll see some premade rulesets for different scenarios. Once you install auditd on Ubuntu, you'll have audit rules for it too, but the location is different for Ubuntu 16.04 and Ubuntu 18.04. On Ubuntu 16.04, the rules are in the /usr/share/doc/auditd/examples/ directory. On Ubuntu 18.04, they're in the /usr/share/doc/auditd/examples/rules/ directory. In any case, some of the rulesets are common among all three of these distros. Let's look at the CentOS 7 machine to see what we have there:
[donnie@localhost rules]$ pwd/usr/share/doc/audit-2.7.6/rules[donnie@localhost ...