On Thursday 28 August 2008 06:40:01 Peng Haitao wrote:
The value of "acct=" which is not in double quotation,
cannot be right
gotten.
The log is:
type=USER_CHAUTHTOK msg=audit(1167580800.033:178653): user pid=23192 uid=0
auid=0 subj=root:system_r:unconfined_t:s0-s0:c0.c1023 msg='op=adding user
acct=aulog exe="/usr/sbin/useradd" (hostname=?, addr=?, terminal=pts/6
res=success)'
Thanks for providing the log entry that causes a problem. How does this show
up as a problem in ausearch or aureport?
Thanks,
-Steve