Policy for the kernel message logger and system logging daemon.
All of the rules required to administrate the logging environment
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
User role allowed access. |
All of the rules required to administrate the audit environment
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
User role allowed access. |
All of the rules required to administrate the syslog environment
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
User role allowed access. |
Append to all log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Check if syslogd is executable.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create a domain for processes which can be started by the system audit dispatcher
Parameter: | Description: |
---|---|
domain |
Type to be used as a domain. |
entry_point |
Type of the program to be used as an entry point to this domain. |
Execute auditctl in the auditctl domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute auditd in the auditd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute a domain transition to run the audit dispatcher.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Execute klogd in the klog domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute syslogd in the syslog domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to get the atttributes of any log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
dontaudit search of auditd configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Do not audit attempts to search the var log directory.
Parameter: | Description: |
---|---|
domain |
Domain not to audit. |
dontaudit attempts to send audit messages.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Dontaudit Write generic log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute all log files in the caller domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
List the contents of the generic log directory (/var/log).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Make the specified type a file used for logs.
Parameter: | Description: |
---|---|
file_type |
Type of the file to be used as a log. |
Create an object in the log directory, with a private type using a type transition.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
private type |
The type of the object to be created. |
object |
The object class of the object being created. |
Create, read, write, and delete all log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage the auditd configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Manage the audit log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Create, read, write, and delete generic log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read all log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the auditd configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read the audit log.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read generic log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read syslog configuration files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Execute auditctl in the auditctl domain, and allow the specified role the auditctl domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to be allowed the auditctl domain. |
Execute auditd in the auditd domain, and allow the specified role the auditd domain.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
role |
The role to be allowed the auditd domain. |
read/write to all log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write the generic log directory (/var/log).
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Read and write generic log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Allows the domain to open a file in the log directory, but does not allow the listing of the contents of the log directory.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send audit messages.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Send system log messages.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set up audit
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Set login uid
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Signal the audit dispatcher.
Parameter: | Description: |
---|---|
domain |
Domain allowed to transition. |
Connect to auditdstored over an unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Connect to the audit dispatcher over an unix stream socket.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |
Write generic log files.
Parameter: | Description: |
---|---|
domain |
Domain allowed access. |