On Friday 25 December 2009 03:49:39 am 陈洁丹 wrote:
But when I copy the audisp-example to /sbin/, and copy the configure
file
audisp-example.conf to /etc//etc/audisp/plugins.d
restart the auditd, it didnot work.
I would need to see the contents of your audisp-example.conf file to
understand. The technique is real simple. It parses the conf file and looks for
the path variable and executes what it points to. The file should have
executable permissions and owned by root.
-Steve