Im trying to monitor the start and stop of processes on a server with auditdauditd, using the following rule
-w /usr/bin/ -p x -k T1569.002
-w /usr/bin/ -p x -k T1569.002
howeverHowever, when raising an event to generate the log and searching it whit ausearchwith ausearch, the only log it fibdsfinds is the addition of the rule.