Audit key options#1882
Merged
albertomn86 merged 9 commits into3.7from Nov 16, 2018
Merged
Conversation
Contributor
Author
|
The included fields have been redesigned to add external audit keys. A tag has been created for the options of Whodata and within it the rest of options will be added, among them Finally the configuration will be the following one: |
albertomn86
approved these changes
Nov 16, 2018
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issues:
Added two new options to manage audit events:
The way these keys are displayed in the audit log varies depending on the characters entered. If you enter the character
(whitespace) or"(double quote) the key will be generated in hexadecimal. It will also do so when the decimal value of the character is greater than 126 (extended ASCII).Tests:
Audit allows inserting spaces inside the keys, so the spaces inserted inside the field <audit_extra_key> will be part of the key.
auditctl -wand introduce those string in the option<audit_extra_key></audit_extra_key>. Check that alerts of these directories appear. Check that the event generated in audit.log was generated with the key created byauditctland not with thekey=wazuh_fim.