Hi,
The redhat security guide in annex B2 reads :
All Audit event types prepended with
ANOM
are intended to be processed by an intrusion detection program.
All Audit event types prepended with
RESP
are intended responses of an intrusion detection system in case it detects malicious activity on the system.
Can you point me towards an intrusion detection program able to manage these audit records.
Thanks
Philippe