Hello,
I've just released a new version of the audit daemon. It can be
downloaded from
http://people.redhat.com/sgrubb/audit. It will also be
in rawhide soon. The ChangeLog is:
- Update TRUSTED_APP interpretation to look for known fields
- In auditd plugins, allow variable amount of arguments (Attila Lakatos)
- Fix augenrules to work correctly when kernel is in immutable mode
- Add ausearch_cur_event to auparse library (Attila Lakatos)
- Add audisp-filter plugin (Attila Lakatos)
- Improve sorting speed of aureport --summary reports
- auditd & audit-rules.service pick up paths automatically (Laurent Bigonville)
- Update auparse normalizer for new syscalls
This is a mix of bug fixes and new features. The new feature is the
audisp-filter auditd plugin. It can chain together another plugin and filter
the events being passed to the other plugin. Also, there has been some more
performance work to see if we can get reporting and interpreting fields
running as fast as possible.
If you notice any problems with this release, please let me know.
SHA256: 3890319b8536446d70801e20a5790c63e879f99be83875a858460641c6c7aff4
-Steve