什么是审计
审计案例
部署audit
[root@sheji57 ~]# yum -y install audit
[root@sheji57 ~]# systemctl start auditd
[root@sheji57 ~]# systemctl enable auditd
定义临时规则
[root@sheji57 ~]# auditctl -w /etc/passwd -p wa -k passwd_abc
[root@sheji57 ~]# auditctl -w /etc/selinux/ -p wa -k selinux_bcd
[root@sheji57 ~]# auditctl -w /usr/sbin/fdisk -p x -k fdisk_efd
[root@sheji57 ~]# auditctl -l
-w /etc/passwd -p wa -k passwd_abc
-w /etc/selinux -p wa -k selinux_bcd
-w /usr/sbin/fdisk -p x -k fdisk_efd
定义永久规则
将规则写入配置文件/etc/audit/rules.d/audit.rules
[root@sheji57 ~]# ls /var/log/audit/audit.log //查看audit日志文件
[root@sheji57 ~]# vim /etc/audit/rules.d/audit.rules
末尾追加:
-w /etc/passwd -p wa -k passwd_abc
-w /etc/selinux -p wa -k selinux_bcd
-w /usr/sbin/fdisk -p x -k fdisk_efd
[root@sheji57 ~]# ausearch -k passwd_abc //查看规则项passwd_abc记录日志
查看日志