Is there a rule for auditing all processes' syscall info?

Marius.bao marius.bao at gmail.com
Sat Dec 29 01:30:45 UTC 2007


Hi all,
    We can use a rule to audit one specific process's all syscall info,
eg: auditctl -a entry,always -S all -F pid=1005, it will log process 1005's
syscall info. Is there a rule available to audit all processes' syscall
info?

Thanks in advance.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/linux-audit/attachments/20071229/62b3c022/attachment.htm>


More information about the Linux-audit mailing list