Open jw3 opened 10 months ago
Noticed during V1.3 testing and verified with @jw3 and in rust libs, that only simple checking of fields has been implemented up to this point. An image says it best:
There are only specific syslog field values and filesystem type values that are valid. See man fapolicyd.conf
for those specifics associated with the fapolicyd
version as a starting point.
Need parsing implementations for
watch_fs
andsyslog_format
ht: @tparchambault