According to the Redhat 7 security guide ANOM_ROOT_TRANS is triggered when a user becomes root.
It seems that using sudo doesn’t trigger this event.
I would like to know how this event is triggered.
There are also several ANOM_ types that I can’t see generated.
Is there a document describing from where these event would come.