Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal for new Linux auditdline_test #114

Open
ebouillard opened this issue Feb 15, 2021 · 1 comment
Open

Proposal for new Linux auditdline_test #114

ebouillard opened this issue Feb 15, 2021 · 1 comment
Labels
Add to Existing Schema A proposal for the addition of a new Test/Object/State to an existing OVAL schema Linux Issue related to the Linux schema.

Comments

@ebouillard
Copy link

ebouillard commented Feb 15, 2021

Abstract
The auditdline_test is used to check the living rules of the auditd service.

Link to Proposal
#115

@vojtapolasek
Copy link

Hello,
thank you for this contribution. It looks very interesting. I looked at the auditd_line test. Have you considered using more filters than just "key" for the auditd_line_object? It would be nice to be able to select a line through regexp match against the whole rule line and then check some parameters within the state, e.g. line number.
To add some context; it would be great to be able to if certain rules are in certain order, e.g. more specific rules are preceding more general rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Add to Existing Schema A proposal for the addition of a new Test/Object/State to an existing OVAL schema Linux Issue related to the Linux schema.
Projects
None yet
Development

No branches or pull requests

3 participants