Re: Google Chrome generates many audit type 1326 messages

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 12/29/2016 03:57 PM, Patrick O'Callaghan wrote:
> On Thu, 2016-12-29 at 10:53 -0800, Rick Stevens wrote:
>>> Which seems to indicate that the boolean is already set, but the audit flood continues.
>>
>> Ok, yeah, that's what I've got.
>>
>> As to the auditctl line, the "exe=" clause can only be used on the
>> "exit" list. I think what you want is:
>>
>>         sudo auditctl -a exit,never -F exe=/opt/google/chrome/chrome
>>
>> e.g. "append a rule to the exit list so that it never generates an
>> audit record for that executable".
> 
> I think you're right, though it requires a close reading of the man
> page to understand this. Anyway I've enabled it in the audit rules and
> so far it seems to work.

Huzzah! Hope that's "the magic bullet" for you.
----------------------------------------------------------------------
- Rick Stevens, Systems Engineer, AllDigital    ricks@xxxxxxxxxxxxxx -
- AIM/Skype: therps2        ICQ: 226437340           Yahoo: origrps2 -
-                                                                    -
-   To understand recursion, you must first understand recursion.    -
----------------------------------------------------------------------
_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx



[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]
  Powered by Linux