In this section, we will see how to use ausearch and aureport tools to read the log files of the auditd daemon and create reports from them:
- The default location to find the logs of auditd is /var/log/audit/audit.log. If we view the content of this file, we get an output as shown here:
As we can see in this output, the log contains lots of data, and us it is difficult to get a specific information from this file, just by viewing its content.
- Hence, we will use ausearch to search through the logs in a more powerful and efficient way. First, we check the help file of the tool to understand the options that can be used: