Skip to content

Adapting an OpenBSM auditdistd to serve as a Linux Audit audisp plugin capable of sending audit trails over to a FreeBSD auditdistd.

Notifications You must be signed in to change notification settings

0mp/audisp-auditdistd

Repository files navigation

audisp-auditdistd

Pushing audit logs from Linux over to FreeBSD using auditdistd daemons.

Usage

First set up

./generate-auditdistd-conf
./do-vagrant-up
./do-provision
vagrant provision linux-sender --provision-with rebuild-openbsm

Run auditdistds

vagrant provision freebsd-receiver --provision-with run
vagrant provision linux-sender --provision-with run

Detatils

There are 3 machines:

  • freebsd-receiver
  • freebsd-sender
  • linux-sender

The goal is to make linux-sender work flawlessly with freebsd-receiver.

freebsd-sender is here for debugging purposes. In order to start the freebsd-sender machine you have to run:

./do-vagrant-up --full

Every machine has its own OpenBSM branch.

Dependencies

  • rsync
  • vagrant

About

Adapting an OpenBSM auditdistd to serve as a Linux Audit audisp plugin capable of sending audit trails over to a FreeBSD auditdistd.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages