## This is for don't audit rules. We put these early because audit ### is a first match wins system. Uncomment the rules you want. ## Cron jobs fill the logs with stuff we normally don't want #-a never,user -F subj_type=crond_t ## This prevents chrony from overwhelming the logs #-a never,exit -F arch=x86_64 -S adjtimex -F auid=unset -F uid=chrony -F subj_type=chronyd_t ### This is not very interesting and wastes a lot of space if ### the server is public facing #-a always,exclude -F msgtype=CRYPTO_KEY_USER
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
10-base-config.rules | File | 163 B | 0644 |
|
10-no-audit.rules | File | 284 B | 0644 |
|
11-loginuid.rules | File | 93 B | 0644 |
|
12-cont-fail.rules | File | 329 B | 0644 |
|
12-ignore-error.rules | File | 323 B | 0644 |
|
20-dont-audit.rules | File | 516 B | 0644 |
|
21-no32bit.rules | File | 273 B | 0644 |
|
22-ignore-chrony.rules | File | 252 B | 0644 |
|
23-ignore-filesystems.rules | File | 506 B | 0644 |
|
30-nispom.rules | File | 4.8 KB | 0644 |
|
30-ospp-v42.rules | File | 10.15 KB | 0644 |
|
30-pci-dss-v31.rules | File | 5.81 KB | 0644 |
|
30-stig.rules | File | 6.44 KB | 0644 |
|
31-privileged.rules | File | 1.42 KB | 0644 |
|
32-power-abuse.rules | File | 213 B | 0644 |
|
40-local.rules | File | 156 B | 0644 |
|
41-containers.rules | File | 439 B | 0644 |
|
42-injection.rules | File | 672 B | 0644 |
|
43-module-load.rules | File | 398 B | 0644 |
|
70-einval.rules | File | 326 B | 0644 |
|
71-networking.rules | File | 151 B | 0644 |
|
99-finalize.rules | File | 86 B | 0644 |
|
README-rules | File | 1.17 KB | 0644 |
|