Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Aureport on stream of data #324

Closed
chazoz opened this issue Sep 17, 2023 · 7 comments
Closed

Aureport on stream of data #324

chazoz opened this issue Sep 17, 2023 · 7 comments

Comments

@chazoz
Copy link

chazoz commented Sep 17, 2023

I would like to know how can I rum aureport on a stream of data, i.e auditd logs streamed to elk

@stevegrubb
Copy link
Member

I have never seen any output of elk. So, I can't really help there. But if you can get it formatted just like the original audit logs, then you can pipe it into aureport via stdin. Not much I can do with this one.

Issue #130 also asks for acceptance of other formats. But it is low priority.

@chazoz
Copy link
Author

chazoz commented Sep 20, 2023 via email

@stevegrubb
Copy link
Member

I have no idea what the output is as I have no access to any of those. Once you take the logs into something else, typically you use the tools provided by that something else. If their tools can't extract the data back into its original format, you can't use tools from the original source (auditd).

@chazoz
Copy link
Author

chazoz commented Sep 21, 2023 via email

@stevegrubb
Copy link
Member

Yes. For example, try the following:
ausearch --start today --key module-load --raw | aureport -x --summary -i

@stevegrubb
Copy link
Member

Looks like this ticket can be closed. If you have any further questions just ask.

@chazoz
Copy link
Author

chazoz commented Oct 11, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants