nixCraft Linux Forum

nixCraft

Linux Tech Support Forum

Linux Auditing Problems - log file getting large

This is a discussion on Linux Auditing Problems - log file getting large within the Networking, Firewalls and Security forums, part of the Mastering Servers category; I have yet to find a truly comprehensive solution to auditing Linux to meet NISPOM or DCID government requirements.I have ...


Go Back   nixCraft Linux Forum > Mastering Servers > Networking, Firewalls and Security

Register FAQ Members List Calendar Mark Forums Read
  #1 (permalink)  
Old 05-17-2007, 08:18 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default Linux Auditing Problems - log file getting large

I have yet to find a truly comprehensive solution to auditing Linux to meet NISPOM or DCID government requirements.I have a Red Hat Enterprise 4 WS with SElinux enabled. When I tweak the /etc/audit.rules file using auditctl, I get "invalid argument" for "-w" and "-pa" even though the man pages say this should work. I even tried using the /usr/share/doc/audit-1.2.1/capp.rules file, same problems. not to mention my audit log gets so full so fast on garbage.I then installed Snare. Not impressed, glorified GUI which just regurgitates the raw audit log. How can I configure auditing to only look at FAILED executable access/run attempts?How can I configure auditing to look for FAILED attempts to access specific files?Am I missing a piece to this puzzle? Any help is appreciated.
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-17-2007, 08:49 PM
nixcraft's Avatar
Never say die
User
 
Join Date: Jan 2005
Location: BIOS
My distro: Any distro with shell
Posts: 910
Rep Power: 10
nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute
Default

You need to use ausearch and aureport commands to search log files. For example display all failed attempts
Code:
ureport -f -i --summary --failed
Read man page of above two command and try following resources:
Article about audit log visualization
Audit System FAQ
Linux audit files to see who made changes to a file | nixCraft

Let me know if you need any further help!
__________________
Vivek | My personal blog
Linux Evangelist
Play hard stay cool
Reply With Quote
  #3 (permalink)  
Old 05-17-2007, 08:52 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

Thanks. I'll try that. Still can't figure out why the rules I try to add to audit.rules won't take. Still get "invalid argument" to place watches on files.
Reply With Quote
  #4 (permalink)  
Old 05-17-2007, 08:57 PM
Administrator
User
 
Join Date: Apr 2007
Posts: 10
Rep Power: 10
root has disabled reputation
Default

Quote:
Originally Posted by CrackerJack1618 View Post
Thanks. I'll try that. Still can't figure out why the rules I try to add to audit.rules won't take. Still get "invalid argument" to place watches on files.
Can you paste your complet rule here so that I can look at it...
Reply With Quote
  #5 (permalink)  
Old 05-17-2007, 08:59 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

I created a dummy account, tried deleted and modifying the /etc/shadow file (which I couldn't - got permission denied).

I then logged back in as root and did the command you suggested. it found nothing. Is the SElinux module screwing things up? I disabled it and rebooted, no change. I even removed SNARE. No change.

Thanks for any advice.
Reply With Quote
  #6 (permalink)  
Old 05-17-2007, 09:03 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

From # prompt, I did this and got the below messages:

auditctl -w /etc/auditd.conf -p wa
permission option no longer supported
error sending add rule request (invalid argument)

auditctl -w /etc/auditd.conf
error sending add rule request (invalid argument)

It won't let me add rules. The capp.rules file I found is full of the above commands for various security relevant files. Each line with -w or -p says invlaid argument when I restart AUDITD.

I restored the original audit.rules file 9whcih I saved) and did the above - No change.

audit.rules has these lines by default:
-D
-b 256

that's it.
Reply With Quote
  #7 (permalink)  
Old 05-17-2007, 09:42 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

FYI - With SNARE off (disabled dispatcher in auditd.conf), the audit log sizes are manageable. When I turn Snare back on, I get 30-40 MB on a reboot alone.

Here are some of the "failures" that Snare reports (on a reboot):

Failed File Summary Report
===========================
total file
===========================
699 /root/Templates
351 /dev/sda
10 /usr/share/locale/en_US.UTF-8/LC_TIME/coreutils.mo
10 /usr/share/locale/en_US/LC_TIME/coreutils.mo
10 /usr/share/locale/en.UTF-8/LC_TIME/coreutils.mo
10 /usr/share/locale/en.utf8/LC_TIME/coreutils.mo
10 /usr/share/locale/en/LC_TIME/coreutils.mo
10 /usr/share/locale/en_US.UTF-8/LC_MESSAGES/coreutils.mo
10 /usr/share/locale/en_US.utf8/LC_MESSAGES/coreutils.mo
10 /usr/share/locale/en_US/LC_MESSAGES/coreutils.mo
10 /usr/share/locale/en.UTF-8/LC_MESSAGES/coreutils.mo
10 /usr/share/locale/en.utf8/LC_MESSAGES/coreutils.mo
10 /usr/share/locale/en/LC_MESSAGES/coreutils.mo
9 /usr/share/locale/en_US.utf8/LC_TIME/coreutils.mo
2 /dev/tty
2 /lib/security/$ISA/pam_deny.so
2 /usr/share/locale/en/LC_MESSAGES/util-linux.mo
2 /usr/share/locale/en.utf8/LC_MESSAGES/util-linux.mo
2 /usr/share/locale/en.UTF-8/LC_MESSAGES/util-linux.mo
2 /usr/share/locale/en_US/LC_MESSAGES/util-linux.mo
2 /usr/share/locale/en_US.utf8/LC_MESSAGES/util-linux.mo
2 /usr/share/locale/en_US.UTF-8/LC_MESSAGES/util-linux.mo
1 /usr/share/locale/en_US.UTF-8/LC_MESSAGES/libc.mo
1 /usr/share/locale/en_US.utf8/LC_MESSAGES/libc.mo
1 /usr/share/locale/en_US/LC_MESSAGES/libc.mo
1 /usr/share/locale/en.UTF-8/LC_MESSAGES/libc.mo
1 /usr/share/locale/en.utf8/LC_MESSAGES/libc.mo
1 /usr/share/locale/en/LC_MESSAGES/libc.mo
1 /usr/share/locale/en_US.UTF-8/LC_MESSAGES/initscripts.mo
1 /usr/share/locale/en_US.utf8/LC_MESSAGES/initscripts.mo
1 /usr/share/locale/en_US/LC_MESSAGES/initscripts.mo
1 /usr/share/locale/en.UTF-8/LC_MESSAGES/initscripts.mo
1 /usr/share/locale/en.utf8/LC_MESSAGES/initscripts.mo
1 /usr/share/locale/en/LC_MESSAGES/initscripts.mo
1 /lib/security/$ISA/pam_env.so
1 /lib/security/$ISA/pam_unix.so
1 /lib/security/$ISA/pam_smb_auth.so
1 /lib/security/$ISA/pam_succeed_if.so
1 /lib/security/$ISA/pam_permit.so
1 /lib/security/$ISA/pam_cracklib.so
1 /lib/security/$ISA/pam_limits.so

I can't understand why these are failures. Right now I have to leave Snare (dispatcher) disabled.
Reply With Quote
  #8 (permalink)  
Old 05-17-2007, 09:43 PM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

This may be of importance - I did NOT install the SNARE Kernel because Security Alliance has not posted a version yet for my kernel version 2.6.9-42. All they have is 2.6.9-34. Could this be my problem? I am trying to erase Snare completely right now. I may have to rebuild without it and start from there.
Reply With Quote
  #9 (permalink)  
Old 05-18-2007, 01:31 AM
Junior Member
User
 
Join Date: May 2007
My distro: Red Hat Enterprise Linux 4
Posts: 7
Rep Power: 0
CrackerJack1618 is on a distinguished road
Default

Re-installed Redhat Linux 4 from scratch and re-traced some install steps. Not sure if issue between audit-1.0.15 an 1.2 or not. Discovered that you should NOT install the Snare CORE AND the agenct. Most likely the culprit. Thanks for the help anyway.

Now to see if I can get some files to pull in the audit log.
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
HPUX Unix comparing 2 large files line by line raj HP-UX 1 02-11-2008 05:20 PM
why can't forward large email attachment? khaosregion Mail Servers 4 10-25-2007 11:49 PM
PHPMyAdmin Problems JoeDively Coding in General 0 09-21-2007 09:30 PM
nfs problems marros Linux software 2 10-21-2006 01:30 AM
Program gets aborted on large input Ssk Linux software 7 03-14-2005 11:04 AM


All times are GMT +5.5. The time now is 05:11 PM.


Powered by vBulletin® Version 3.7.2 - Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36