On 06/11/2013 04:04 PM, LC Bruzenak wrote:
I was playing with audit rules using keys with spaces.
Is the following expected (ignore the logic; was just testing the returns)?
# auditctl -l -k lsmod
LIST_RULES: exit,always watch=/sbin/lsmod perm=x key=lsmod kernel
LIST_RULES: exit,always watch=/bin/ping perm=x key=lsmod ping
Thx,
LCB
Sorry - forgot the version : audit-2.2-1.
Thx,
LCB
--
LC (Lenny) Bruzenak
lenny(a)magitekltd.com