How to do it...

In this section, we will see how to use ausearch and aureport tools to read the log files of the auditd daemon and create reports from them:

  1. The default location to find the logs of auditd is /var/log/audit/audit.log. If we view the content of this file, we get an output as shown here:

As we can see in this output, the log contains lots of data, and us it is difficult to get a specific information from this file, just by viewing its content.

  1. Hence, we will use ausearch to search through the logs in a more powerful and efficient way. First, we check the help file of the tool to understand the options that can be used:

Get Practical Linux Security Cookbook - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.