启动centos audit服务报错
错误信息
$service auditd restart Stopping logging:
[FAILED] Redirecting start to /bin/systemctl start auditd.service Job
for auditd.service failed because the control process exited with
error code. See “systemctl status auditd.service” and “journalctl -xe”
for details.
分析
解决
$ mkdir -p /var/log/audit
$ ll /var/log | grep audit
drwxr-xr-x 2 root root 6 8月 24 17:34 audit
$ service auditd restart
Stopping logging: [FAILED]
Redirecting start to /bin/systemctl start auditd.service
$ systemctl status auditd
OK
OK解决了
附:
配置文件
vim /etc/audit/auditd.conf
$ auditctl -s
enabled 1
failure 1
pid 855204
rate_limit 0
backlog_limit 8192
lost 0
backlog 0
loginuid_immutable 0 unlocked
auditctl -l # list all rules
附link :
https://guoflight.github.io/posts/63889/#:~:text=cat%20%2Fvar%2Flog%2Faudit%2Faudit.log,%E4%BE%8B%E5%A6%82%EF%BC%9A%E8%BF%90%E8%A1%8C%E5%91%BD%E4%BB%A4rm%20-rf%20%2Froot%2F123