0

Im trying to monitor the start and stop of processes on a server with auditd, using the following rule

-w /usr/bin/ -p x -k T1569.002

However, when raising an event to generate the log and searching it with ausearch, the only log it finds is the addition of the rule.

3
  • If the process is already loaded into memory, /usr/bin is not referenced on startup. Not all executables come from /usr/bin. Nor is the filesystem referenced at all on process exit. Commented Jul 19, 2024 at 22:34
  • If you want to monitor process start/stop, you probably want to monitor the execve and exit system calls. Take a look at this article. Commented Jul 23, 2024 at 16:01
  • See sematext.com/blog/linux-monitoring-tools and cyberciti.biz/tips/top-linux-monitoring-tools.htm and do an intrrnet search on "Perfomance Accounting" Performance Monitoring". Be prepared to drink from the firehose of data if you track process statt/stop. Commented Jul 23, 2024 at 18:00

0

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.