{"id":701,"date":"2018-08-08T01:56:39","date_gmt":"2018-08-08T01:56:39","guid":{"rendered":"http:\/\/hyderabadwebhosting.in\/blog\/?p=701"},"modified":"2018-08-06T01:57:38","modified_gmt":"2018-08-06T01:57:38","slug":"how-to-change-the-path-of-the-auditd-log-file-var-log-audit-audit-log","status":"publish","type":"post","link":"https:\/\/hyderabadwebhosting.in\/blog\/how-to-change-the-path-of-the-auditd-log-file-var-log-audit-audit-log\/","title":{"rendered":"How to change the path of the auditd log file \/var\/log\/audit\/audit.log"},"content":{"rendered":"<p><strong><span style=\"font-size: large;\">How to change the path of the auditd log file \/var\/log\/audit\/audit.log<\/span><\/strong><\/p>\n<p><span style=\"font-size: large;\">An important task related to troubleshooting can arise from an understanding of activities commonly associated with the action of reading and writing files. Linux provides a simple utility for this. Known as auditd, this service (or daemon) starts during the boot process. Events are recorded to an associated log file found at \/var\/log\/audit and as it runs in the background, you can check the current service status with below command in case of CentOS\/RHEL 7 server:<\/span><\/p>\n<pre class=\"lang:default decode:true \"># systemctl status auditd<\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: large;\">It is possible to customize the auditing service and you can have direct access to manage the log file size, location, and associated attributes by accessing the following file with your favorite text editor:<\/span><\/p>\n<pre class=\"lang:default decode:true \"># vi \/etc\/audit\/auditd.conf<\/pre>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"font-size: large;\">Changing the default log file location for auditd<\/span><\/strong><\/p>\n<p><span style=\"font-size: large;\">1. In the auditd configuration file \/etc\/audit\/auditd.conf, change the option log_file = \/var\/log\/audit\/audit.log so that it points to the new path, e. g.:<\/span><\/p>\n<pre class=\"lang:default decode:true\"># vi \/etc\/audit\/auditd.conf\r\n\r\nlog_file = \/auditd_logs\/audit.log<\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: large;\">2. If you have the SELinux enabled, configure default SELinux file context labels for the new path and restore the security contexts accordingly:<\/span><\/p>\n<pre class=\"lang:default decode:true \"># semanage fcontext -a -e \/var\/log\/audit '\/auditd_logs(\/.*)?'\r\n\r\nrestorecon -Rv \/auditd_logs<\/pre>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: large;\">3. Restart the auditd service for the changes to take effect.<\/span><\/p>\n<pre class=\"lang:default decode:true \"># systemctl restart auditd<\/pre>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"font-size: large;\">Verify<\/span><\/strong><\/p>\n<p><span style=\"font-size: large;\">You can check the new log file \/auditd_logs\/audit.log getting the new auditd logs written to. Also from now on, when using the ausearch command, add the -if or \u2013input-logs switches:<\/span><\/p>\n<pre class=\"lang:default decode:true \"># ausearch -if \/auditd_logs\/audit.log -m avc -i -ts recent<\/pre>\n<p>&nbsp;<\/p>\n<div class=\"pdf24Plugin-cp\"> \t<form name=\"pdf24Form0\" method=\"post\" action=\"https:\/\/doc2pdf.pdf24.org\/wordpress.php\" target=\"pdf24PopWin\" onsubmit=\"var pdf24Win = window.open('about:blank', 'pdf24PopWin', 'resizable=yes,scrollbars=yes,width=600,height=250,left='+(screen.width\/2-300)+',top='+(screen.height\/3-125)+''); pdf24Win.focus(); if(typeof pdf24OnCreatePDF === 'function'){void(pdf24OnCreatePDF(this,pdf24Win));}\"> \t\t<input type=\"hidden\" name=\"blogCharset\" value=\"Cw1x07UAAA==\" \/><input type=\"hidden\" name=\"blogPosts\" value=\"MwQA\" \/><input type=\"hidden\" name=\"blogUrl\" value=\"yygpKSi20tfPqExJLUpMSkwpT03KyC8uycxL18vM00\/KyU8HAA==\" \/><input type=\"hidden\" name=\"blogName\" value=\"86hMSS1KTEpMUQhPTVLwyC8uycxLBwA=\" \/><input type=\"hidden\" name=\"blogValueEncoding\" value=\"gzdeflate base64\" \/><input type=\"hidden\" name=\"postId_0\" value=\"MzcwBAA=\" \/><input type=\"hidden\" name=\"postTitle_0\" value=\"88gvVyjJV0jOSMxLT1UoyUhVKEgsyVDITwOzE0tTMktSFHLy0xXSMnNSFfTLEov0gTx9sASE1APyAQ==\" \/><input type=\"hidden\" name=\"postLink_0\" value=\"LYxBDoAgDARfVHv3N8UWSkIogSrx9yrxstnZTFbd29gR9WbpFIinBLXhuaYtVwzFEqpNcINDqSYBV4FGrmBxdTo5O8MrQsxF4KK+YO1\/fi8P\" \/><input type=\"hidden\" name=\"postAuthor_0\" value=\"c\/QLDVAICHJ08XD0AwA=\" \/><input type=\"hidden\" name=\"postDateTime_0\" value=\"MzIwtNA1ACEFA0MrAwsrY0sA\" \/><input type=\"hidden\" name=\"postContent_0\" value=\"pVbRihs3FH1fyD9cttAkxR7T9qGw2XUJYSGhgcIGCn0KsubOjFhZGqSrcdyn\/kP\/sF\/SI82M7aa7zdZ9sT2WdO+55557NNf9+jpK8K7Fd68cRdlbvrlsvJNlNL\/xFVkVWn51uX7rdySedKdcyyQdU6+kI9+U3yrVRmqyvqXGWKbVoMIKT6uyMH5WeL5e5TRrfE1ZV\/364rr\/YvbXjsy290GUExIV7ymwVcJ1xoRQaWM5dt6LcS1phFLBRKYm+C3hKbmaQ8ThOq8Ds9JiBiOGI2m\/3Xpn96Ri9NqUoDuD0kpd2OddPhFYlcOIQbtgSqJcaqzovXHpE\/XBD6ZGQEURWEFCEmON7KnxAcEMdv7k\/A7Y4sTXovxNkcNgNNML7KsVA81LUKGCRKpTyIkylA2qy0k0R0S6HdhhXQUGMu1DPVKRKz+WcWhH48EAKfmsL6UYoMGvkBy+3ZhJ6fs25CML2vtU+NQd6\/uyqlMIyH1ADaSS4kjZhi1kkhnNkRFOK3QB7L3BiZ8\/rO7e3r6nH8pRDlcHMRQNoBJtAf7m0kJiVzU3KlmhGtXVfCUhMV2uv6K4j8JbLXZOPFKJIIGLlL52m9i\/eqqw3gmhA72P0UBCReEpit9i01HYuQVzubmwmZRODUy1QQNApc6NyQFQu5pG5NCAnHSBR62ynhYT8YdGKZFgNkmgns1+CjX3vfEWpM5yG3kGgECNGjyEiEz8SYiB05\/J6WBoxaJPh7WutHfN46w+zTTeZLeYC5mzH0iZ6SgDMrfxPH\/4tqJ37tSJMnrTpjAlKJ70YImLU0vzfdkOhB\/LkZtHjYwifKfDRGF2em\/yLGYnQgzHu2KNC+KK2uo\/d+RfG\/Ls4tnFKbpx6SP+iqcme94sfAcSmyLuIuxczIfb0dzYKYwH\/GDm9djOeUuBhOWiRqtgBXFyviMnRfeBMWBhjB8ZdpI9cjoYs\/jhZtCM3Z9pEDwNYDODWSpafn4l0fNT7l6sqm9e\/vg8szuhw1la3g1\/Y\/hcXr+v6I6LoZ8qdDaUmaNRhqOM1D0TNw18pfqfJhmmxF9yyafN8y8cTLM\/d0h\/\/cddknVxfGd4UMzUsshsIXn\/8VUjlotYGIPvK3ptMZLlwsclS9lkdx2W0sFIVYqsgu7m+wkuXNdlZWkaQhf+\/P0P4\/okyxI7wmmBNJ6nwkOyHPuRypZ4Nxk0dtASwofmcEk+2KG\/AA==\" \/> \t\t<a href=\"https:\/\/www.pdf24.org\" target=\"_blank\" title=\"www.pdf24.org\"><img src=\"https:\/\/hyderabadwebhosting.in\/blog\/wp-content\/plugins\/pdf24-post-to-pdf\/img\/sheep_32x32.png\" alt=\"www.pdf24.org\" border=\"0\" height=\"32\" \/><\/a> \t\t<span class=\"pdf24Plugin-cp-space\">&nbsp;&nbsp;<\/span> \t\t<span class=\"pdf24Plugin-cp-text\">Send article as PDF<\/span> \t\t<span class=\"pdf24Plugin-cp-space\">&nbsp;&nbsp;<\/span> \t\t<input class=\"pdf24Plugin-cp-input\" style=\"margin: 0px;\" type=\"text\" name=\"sendEmailTo\" placeholder=\"Enter email address\" \/> \t\t<input class=\"pdf24Plugin-cp-submit\" style=\"margin: 0px;\" type=\"submit\" value=\"Send\" \/> \t<\/form> <\/div>","protected":false},"excerpt":{"rendered":"<p>How to change the path of the auditd log file \/var\/log\/audit\/audit.log An important task related to troubleshooting can arise from an understanding of activities commonly associated with the action of reading and writing files. Linux provides a simple utility for this. Known as auditd, this service (or daemon) starts during the boot process. Events are\u2026 <span class=\"read-more\"><a href=\"https:\/\/hyderabadwebhosting.in\/blog\/how-to-change-the-path-of-the-auditd-log-file-var-log-audit-audit-log\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","footnotes":""},"categories":[6],"tags":[],"class_list":["post-701","post","type-post","status-publish","format-standard","hentry","category-vps"],"_links":{"self":[{"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/comments?post=701"}],"version-history":[{"count":1,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/701\/revisions"}],"predecessor-version":[{"id":702,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/701\/revisions\/702"}],"wp:attachment":[{"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/media?parent=701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/categories?post=701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hyderabadwebhosting.in\/blog\/wp-json\/wp\/v2\/tags?post=701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}