Closed SHWETHABHAT1 closed 2 weeks ago
There is no support for an all keyword for msgtype. It would be the same as just matching on -F auid=-1. But, that will also lose events about daemons. The hardwired events are mostly located 1100 - 1199 and 2400 - 2600. The BPF event is also pretty useless. If I were you, I'd collect some events for a period of time and then run aureport --event --summary -i for that period of time. That would give you an ordered list of what events are in your logs. You can probably get rid of 90% with less than 10 rules that match an exact msgtype.
Currently support not possible
NOTE: Please refer to the Reporting Bug and Requesting Features wiki page before creating any new GitHub issues.
Requirement: I want to see if there is a rule/option to exclude all hardwired events, if auid=unset.
Rules Tried: -a always,exclude -F msgtype=ALL -F auid=-1
The above rule throws below error when executed augenrules --load.
But in ausearch, we have a option for including all the message types.
If ALL is not supported in rules, is there a page to see what are all the supported and different ways to give msgtypes ? Any help would be appreciated.
@stevegrubb