slackbuilds/system/audit
B. Watson 8531fee5e3 system/audit: Wrap README at 72 columns.
Signed-off-by: B. Watson <yalhcru@gmail.com>
2022-03-17 12:38:03 -04:00
..
README system/audit: Wrap README at 72 columns. 2022-03-17 12:38:03 -04:00
README.SLACKWARE
audit-2.3.6-sysconfig.diff
audit.SlackBuild system/audit: Remove .la files. 2022-03-08 09:44:48 +07:00
audit.info system/audit: Updated for version 3.0.7. 2022-02-13 09:17:46 +07:00
doinst.sh
slack-desc

README

Audit for Slackware

The Linux Auditing System is a kernel subsystem the allows the
kernel to record events of interest to intrusion detection systems,
such as file access attempts, specific system calls, or custom events
generated by trusted system binaries like login or sshd. The audit
package provides the tools to configure the audit system, and to
collect and process its output.

To collect audit events, your kernel must have the audit system
enabled, which is present in the stock Slackware kernels.

The audit package has no other dependencies. However, certain audit
events of interest, such as failed login attempts from /bin/login,
password changes, etcetera are generated by their respective binaries
using libaudit. If your site policy requires auditing those events,
some reconfiguration and/or patching may be required.