Skip to content

Commit 9bbc7dd

Browse files
Saeid Hassan-AbadiSaeid Hassan-Abadi
authored andcommitted
changed filter
1 parent 2ff228f commit 9bbc7dd

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

filter-10-selinux.conf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@ filter {
22
grok {
33
add_tag => "selinux"
44
tag_on_failure => "selinux_failure"
5-
overwrite => "[audit_type, audit_epoch, audit_counter]"
6-
match => [ "message", "type=%{DATA:selinux_audit_type} msg=audit\(%{NUMBER:selinux_audit_epoch}:%{NUMBER:selinux_audit_counter}\): avc:%{SPACE}%{SPACE}%{DATA:selinux_avc} \{ %{WORD:selinux_action} \} for pid=%{NUMBER:selinux_pid} comm=\"%{DATA:selinux_command}\" ((src=%{DATA:selinux_source})?|(name=\"%{DATA:selinux_filename}\" dev=\"%{DATA:selinux_device}\" ino=%{NUMBER:selinux_inode})?) scontext=%{DATA:selinux_source_context} tcontext=%{DATA:selinux_target_context} tclass=%{DATA:selinux_target_class} permissive=%{NUMBER:selinux_permissive}" ]
5+
match => [ "message", ": avc:%{SPACE}%{SPACE}%{DATA:[selinux][avc]} \{ %{WORD:[selinux][action]} \} for pid=%{NUMBER:[selinux][pid]} comm=\"%{DATA:[selinux][command]}\" ((src=%{DATA:[selinux][source]})?|(name=\"%{DATA:[selinux][filename]}\" dev=\"%{DATA:[selinux][device]}\" ino=%{NUMBER:[selinux][inode]})?) scontext=%{DATA:[selinux][source][context]} tcontext=%{DATA:[selinux][target][context]} tclass=%{DATA:[selinux][target][class]} permissive=%{NUMBER:[selinux][permissive]}" ]
76
}
87
}
8+

0 commit comments

Comments
 (0)