Hello,
I've just released a new version of the audit daemon. It can be downloaded
from
http://people.redhat.com/sgrubb/audit It will also be in rawhide
tomorrow. The Changelog is:
- In auditctl -l, loop until all rules are printed
- Update autrace not to run if rules are currently loaded
- Added code to allow switching to single user mode when disk is full
- Added the ausearch program
The big news in this release is finally having the first draft of the ausearch
program. There are a few things that are not working yet. -hn & -f. Besides
getting those options working, I am planning to add the ability for it to
interpret all numeric attributes. And I have plans to change the format so
that its easier to understand. Both of these will be enabled by new command
line options.
Let me know if you have any problems.
-Steve