[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]
Re: audit2allow -M local < /tmp/avcs ?
- From: drago01 <drago01 gmail com>
- To: "Frank Murphy" <frankly3d gmail com>
- Cc: fedora-selinux-list <fedora-selinux-list redhat com>
- Subject: Re: audit2allow -M local < /tmp/avcs ?
- Date: Mon, 7 Jul 2008 11:27:33 +0200
On Mon, Jul 7, 2008 at 11:13 AM, Frank Murphy <frankly3d gmail com> wrote:
> On Mon, 2008-07-07 at 11:08 +0200, drago01 wrote:
>> On Mon, Jul 7, 2008 at 11:02 AM, Frank Murphy <frankly3d gmail com> wrote:
>> > [root frank-01 ~]# audit2allow -M local < /tmp/avcs
>> > -bash: /tmp/avcs: No such file or directory
>> >
>> >
>> > Where to go next.
>> >
>> > The logs are mailed to "root localhost" by exim.
>> >
>> > What and where need to be allowed.
>> >
>> > Have already done a /sbin/fixfiles relabel. (mislabelled stuff)
>> >
>> > To allow for future logs?
>>
>> /tmp/avcs ??
>
> I took that verbatim from faq, rather new to this selinux thingey.
>
>> The logs are either in /var/log/audit.log (if audit is running)
>> otherwise in syslog (in this case passing -D to audit2allow will use
>> them)
>
> audit2allow /var/log/audit/audit.log?
yes just use this file instead of /tmp/avcs
audit2allow -M local < /your/log/file
[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]