Skip to content

System Auditing (auditd)

auditd (Linux Audit Daemon) is a kernel-level security auditing framework for Linux that can record system calls, file access, user operations, and other critical events. It is an essential tool for meeting security compliance requirements such as PCI-DSS, HIPAA, and similar standards.

Most enterprise Linux distributions come with auditd pre-installed. If it is not installed:

Terminal window
sudo dnf install audit audit-libs -y
Terminal window
sudo systemctl enable --now auditd

Check the service status:

Terminal window
sudo systemctl status auditd
ComponentDescription
auditdAudit daemon, responsible for writing audit events to the log
auditctlAudit rule management tool (temporary rules)
ausearchAudit log search tool
aureportAudit log report generation tool
/etc/audit/auditd.confauditd service configuration file
/etc/audit/rules.d/Persistent audit rules directory
/var/log/audit/audit.logAudit log file

auditctl is used to add, delete, and view audit rules at runtime. Rules added via auditctl are temporary and will be lost after a reboot.

Terminal window
sudo auditctl -l
Terminal window
sudo auditctl -s

auditd supports three types of rules:

  1. File system rules (-w): Monitor file or directory access
  2. System call rules (-a): Monitor specific system calls
  3. Control rules (-e, -b, etc.): Control audit system behavior
-w path -p permissions -k keyword

Permission flags:

FlagDescription
rRead
wWrite
xExecute
aAttribute change
Terminal window
# Monitor all modifications to /etc/passwd
sudo auditctl -w /etc/passwd -p wa -k identity
# Monitor all access to /etc/shadow
sudo auditctl -w /etc/shadow -p rwa -k identity
# Monitor modifications to /etc/sudoers
sudo auditctl -w /etc/sudoers -p wa -k sudoers_change
# Monitor modifications to /etc/ssh/sshd_config
sudo auditctl -w /etc/ssh/sshd_config -p wa -k sshd_config
# Monitor modifications to /etc/hosts
sudo auditctl -w /etc/hosts -p wa -k hosts_change
Terminal window
# Monitor all file modifications under /etc/audit/
sudo auditctl -w /etc/audit/ -p wa -k audit_config
# Monitor cron configuration
sudo auditctl -w /etc/cron.d/ -p wa -k cron_change
sudo auditctl -w /etc/crontab -p wa -k cron_change
-a action,filter -S syscall -F field=value -k keyword

Common parameters:

ParameterDescription
-a always,exitAlways log when the system call exits
-SSpecify system call name or number
-F arch=b6464-bit system architecture
-F uid=0Filter by user ID
-F auid>=1000Filter by audit UID (actual login user)
-F auid!=-1Exclude non-login users (system processes)
-kKeyword tag for later searching
Terminal window
# Monitor sudo usage
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation
# Monitor su usage
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation
# Monitor passwd command
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/passwd -k password_change
Terminal window
# Monitor user and group management commands
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_management
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_management
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_management
sudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/groupadd -k user_management
Terminal window
sudo auditctl -a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletion
Terminal window
sudo auditctl -a always,exit -F arch=b64 -S connect -F auid>=1000 -F auid!=-1 -k network_connect
Terminal window
# Delete all temporary rules
sudo auditctl -D
# Delete a specific file monitoring rule
sudo auditctl -W /etc/passwd -p wa -k identity

Temporary rules are lost after a reboot. To make rules persistent, they must be written to files in the /etc/audit/rules.d/ directory.

Terminal window
sudo vi /etc/audit/rules.d/custom.rules

Add the following content:

Terminal window
# Clear existing rules
-D
# Set audit buffer size
-b 8192
# Set failure handling mode (0=silent, 1=print, 2=panic)
-f 1
# ========== File Access Monitoring ==========
# Identity files
-w /etc/passwd -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/group -p wa -k identity
-w /etc/gshadow -p wa -k identity
# SSH configuration
-w /etc/ssh/sshd_config -p wa -k sshd_config
-w /etc/ssh/sshd_config.d/ -p wa -k sshd_config
# Privilege escalation configuration
-w /etc/sudoers -p wa -k sudoers_change
-w /etc/sudoers.d/ -p wa -k sudoers_change
# Audit configuration itself
-w /etc/audit/ -p wa -k audit_config
-w /var/log/audit/ -p wa -k audit_log
# Network configuration
-w /etc/hosts -p wa -k network_config
-w /etc/sysconfig/network-scripts/ -p wa -k network_config
# Scheduled tasks
-w /etc/crontab -p wa -k cron_change
-w /etc/cron.d/ -p wa -k cron_change
-w /var/spool/cron/ -p wa -k cron_change
# ========== Command Execution Monitoring ==========
# Privileged commands
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation
# User management
-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_management
-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_management
-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_management
# File deletion
-a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletion
# System time changes
-a always,exit -F arch=b64 -S adjtimex -S settimeofday -S clock_settime -k time_change
# ========== Lock Rules (place at the end) ==========
# Uncomment the following line to prevent rules from being modified at runtime (requires reboot to change rules)
# -e 2
Terminal window
sudo augenrules --load

Or restart auditd:

Terminal window
sudo service auditd restart

Verify that the rules have been loaded:

Terminal window
sudo auditctl -l

ausearch is a powerful search tool for audit logs.

Terminal window
# Search for identity file change events
sudo ausearch -k identity
# Search for privilege escalation events
sudo ausearch -k privilege_escalation
Terminal window
# Search for today's events
sudo ausearch -k identity -ts today
# Search for events in the last hour
sudo ausearch -k identity -ts recent
# Search a specific time range
sudo ausearch -ts 03/24/2026 09:00:00 -te 03/24/2026 18:00:00
Terminal window
# Search for a specific user's actions
sudo ausearch -ua 1000
# Search for root user's actions
sudo ausearch -ua 0
Terminal window
# Search for login events
sudo ausearch -m USER_LOGIN
# Search for authentication events
sudo ausearch -m USER_AUTH
# Search for system call events
sudo ausearch -m SYSCALL -k file_deletion
Terminal window
# Output in human-readable format
sudo ausearch -k identity -i

The -i flag converts UIDs, GIDs, system call numbers, and more into human-readable names.

Terminal window
sudo ausearch -f /etc/passwd
sudo ausearch -f /etc/shadow -i

aureport generates various audit statistical reports.

Terminal window
sudo aureport --summary
Terminal window
# Authentication report
sudo aureport -au
# Login report
sudo aureport -l
# Failed authentication report
sudo aureport -au --failed
# File access report
sudo aureport -f
# Executable file report
sudo aureport -x
# User report
sudo aureport -u
# System call report
sudo aureport -s
# Anomaly report
sudo aureport --anomaly
# Report by keyword
sudo aureport -k
Terminal window
sudo aureport -au -ts today
sudo aureport -l -ts 03/24/2026 09:00:00 -te 03/24/2026 18:00:00

You can pipe ausearch results into aureport:

Terminal window
# View today's failed login details
sudo ausearch -m USER_LOGIN --failed -ts today | aureport -l
# View file access statistics for a specific keyword
sudo ausearch -k identity | aureport -f --summary
Terminal window
sudo vi /etc/audit/auditd.conf

Key parameters:

# Log file path
log_file = /var/log/audit/audit.log
# Log format (RAW or ENRICHED)
log_format = ENRICHED
# Maximum size of a single log file (MB)
max_log_file = 50
# Action when max size is reached (ROTATE, SYSLOG, SUSPEND, KEEP_LOGS)
max_log_file_action = ROTATE
# Number of log files to retain
num_logs = 10
# Actions when disk space is low
space_left = 75
space_left_action = SYSLOG
admin_space_left = 50
admin_space_left_action = SUSPEND
disk_full_action = SUSPEND
disk_error_action = SUSPEND
  1. Confirm auditd is installed and running:

    Terminal window
    sudo dnf install audit -y
    sudo systemctl enable --now auditd
    sudo auditctl -s
  2. Create an audit rules file:

    Terminal window
    sudo tee /etc/audit/rules.d/security.rules <<'EOF'
    -D
    -b 8192
    -f 1
    # Identity file monitoring
    -w /etc/passwd -p wa -k identity
    -w /etc/shadow -p wa -k identity
    -w /etc/group -p wa -k identity
    -w /etc/sudoers -p wa -k sudoers_change
    -w /etc/sudoers.d/ -p wa -k sudoers_change
    # SSH configuration monitoring
    -w /etc/ssh/sshd_config -p wa -k sshd_config
    # Privileged command monitoring
    -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation
    -a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation
    # User management command monitoring
    -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_mgmt
    -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_mgmt
    -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_mgmt
    # File deletion monitoring
    -a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletion
    EOF
  3. Load the rules:

    Terminal window
    sudo augenrules --load
    sudo auditctl -l
  4. Test that auditing is working correctly:

    Terminal window
    # Modify a monitored file
    sudo touch /etc/passwd
    # Search for the corresponding audit record
    sudo ausearch -k identity -ts recent -i
  5. Generate daily audit reports:

    Terminal window
    # Summary report
    sudo aureport --summary -ts today
    # Authentication report
    sudo aureport -au -ts today
    # Keyword report
    sudo aureport -k -ts today
  6. Optional: Set up an automatic daily report (add a cron job):

    sudo tee /etc/cron.daily/audit-report <<'EOF'
    #!/bin/bash
    aureport --summary -ts yesterday -te today > /var/log/audit/daily-report-$(date +%Y%m%d).txt
    aureport -au --failed -ts yesterday -te today >> /var/log/audit/daily-report-$(date +%Y%m%d).txt
    EOF
    sudo chmod +x /etc/cron.daily/audit-report

auditd is the cornerstone of Linux system security auditing. By properly configuring audit rules, you can comprehensively track critical operations on the system, providing reliable data for security incident investigation and compliance auditing.