System Auditing (auditd)
auditd (Linux Audit Daemon) is a kernel-level security auditing framework for Linux that can record system calls, file access, user operations, and other critical events. It is an essential tool for meeting security compliance requirements such as PCI-DSS, HIPAA, and similar standards.
auditd Basics
Section titled “auditd Basics”Install auditd
Section titled “Install auditd”Most enterprise Linux distributions come with auditd pre-installed. If it is not installed:
sudo dnf install audit audit-libs -yStart the auditd Service
Section titled “Start the auditd Service”sudo systemctl enable --now auditdCheck the service status:
sudo systemctl status auditdauditd Component Overview
Section titled “auditd Component Overview”| Component | Description |
|---|---|
auditd | Audit daemon, responsible for writing audit events to the log |
auditctl | Audit rule management tool (temporary rules) |
ausearch | Audit log search tool |
aureport | Audit log report generation tool |
/etc/audit/auditd.conf | auditd service configuration file |
/etc/audit/rules.d/ | Persistent audit rules directory |
/var/log/audit/audit.log | Audit log file |
Managing Rules with auditctl
Section titled “Managing Rules with auditctl”auditctl is used to add, delete, and view audit rules at runtime. Rules added via auditctl are temporary and will be lost after a reboot.
View Current Rules
Section titled “View Current Rules”sudo auditctl -lCheck Audit System Status
Section titled “Check Audit System Status”sudo auditctl -sAudit Rule Types
Section titled “Audit Rule Types”auditd supports three types of rules:
- File system rules (-w): Monitor file or directory access
- System call rules (-a): Monitor specific system calls
- Control rules (-e, -b, etc.): Control audit system behavior
Monitoring File Access
Section titled “Monitoring File Access”File System Rule Syntax
Section titled “File System Rule Syntax”-w path -p permissions -k keywordPermission flags:
| Flag | Description |
|---|---|
r | Read |
w | Write |
x | Execute |
a | Attribute change |
Monitor Critical Configuration Files
Section titled “Monitor Critical Configuration Files”# Monitor all modifications to /etc/passwdsudo auditctl -w /etc/passwd -p wa -k identity
# Monitor all access to /etc/shadowsudo auditctl -w /etc/shadow -p rwa -k identity
# Monitor modifications to /etc/sudoerssudo auditctl -w /etc/sudoers -p wa -k sudoers_change
# Monitor modifications to /etc/ssh/sshd_configsudo auditctl -w /etc/ssh/sshd_config -p wa -k sshd_config
# Monitor modifications to /etc/hostssudo auditctl -w /etc/hosts -p wa -k hosts_changeMonitor Entire Directories
Section titled “Monitor Entire Directories”# Monitor all file modifications under /etc/audit/sudo auditctl -w /etc/audit/ -p wa -k audit_config
# Monitor cron configurationsudo auditctl -w /etc/cron.d/ -p wa -k cron_changesudo auditctl -w /etc/crontab -p wa -k cron_changeMonitoring Command Execution
Section titled “Monitoring Command Execution”System Call Rule Syntax
Section titled “System Call Rule Syntax”-a action,filter -S syscall -F field=value -k keywordCommon parameters:
| Parameter | Description |
|---|---|
-a always,exit | Always log when the system call exits |
-S | Specify system call name or number |
-F arch=b64 | 64-bit system architecture |
-F uid=0 | Filter by user ID |
-F auid>=1000 | Filter by audit UID (actual login user) |
-F auid!=-1 | Exclude non-login users (system processes) |
-k | Keyword tag for later searching |
Monitor Privileged Commands
Section titled “Monitor Privileged Commands”# Monitor sudo usagesudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation
# Monitor su usagesudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation
# Monitor passwd commandsudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/bin/passwd -k password_changeMonitor User Management Commands
Section titled “Monitor User Management Commands”# Monitor user and group management commandssudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_managementsudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_managementsudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_managementsudo auditctl -a always,exit -F arch=b64 -S execve -F path=/usr/sbin/groupadd -k user_managementMonitor File Deletion Operations
Section titled “Monitor File Deletion Operations”sudo auditctl -a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletionMonitor Network Connections
Section titled “Monitor Network Connections”sudo auditctl -a always,exit -F arch=b64 -S connect -F auid>=1000 -F auid!=-1 -k network_connectDelete Rules
Section titled “Delete Rules”# Delete all temporary rulessudo auditctl -D
# Delete a specific file monitoring rulesudo auditctl -W /etc/passwd -p wa -k identityPersistent Rules: /etc/audit/rules.d/
Section titled “Persistent Rules: /etc/audit/rules.d/”Temporary rules are lost after a reboot. To make rules persistent, they must be written to files in the /etc/audit/rules.d/ directory.
Create a Rules File
Section titled “Create a Rules File”sudo vi /etc/audit/rules.d/custom.rulesAdd the following content:
# Clear existing rules-D
# Set audit buffer size-b 8192
# Set failure handling mode (0=silent, 1=print, 2=panic)-f 1
# ========== File Access Monitoring ==========# Identity files-w /etc/passwd -p wa -k identity-w /etc/shadow -p wa -k identity-w /etc/group -p wa -k identity-w /etc/gshadow -p wa -k identity
# SSH configuration-w /etc/ssh/sshd_config -p wa -k sshd_config-w /etc/ssh/sshd_config.d/ -p wa -k sshd_config
# Privilege escalation configuration-w /etc/sudoers -p wa -k sudoers_change-w /etc/sudoers.d/ -p wa -k sudoers_change
# Audit configuration itself-w /etc/audit/ -p wa -k audit_config-w /var/log/audit/ -p wa -k audit_log
# Network configuration-w /etc/hosts -p wa -k network_config-w /etc/sysconfig/network-scripts/ -p wa -k network_config
# Scheduled tasks-w /etc/crontab -p wa -k cron_change-w /etc/cron.d/ -p wa -k cron_change-w /var/spool/cron/ -p wa -k cron_change
# ========== Command Execution Monitoring ==========# Privileged commands-a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation-a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation
# User management-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_management-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_management-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_management
# File deletion-a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletion
# System time changes-a always,exit -F arch=b64 -S adjtimex -S settimeofday -S clock_settime -k time_change
# ========== Lock Rules (place at the end) ==========# Uncomment the following line to prevent rules from being modified at runtime (requires reboot to change rules)# -e 2Load Persistent Rules
Section titled “Load Persistent Rules”sudo augenrules --loadOr restart auditd:
sudo service auditd restartVerify that the rules have been loaded:
sudo auditctl -lSearching Audit Logs with ausearch
Section titled “Searching Audit Logs with ausearch”ausearch is a powerful search tool for audit logs.
Search by Keyword
Section titled “Search by Keyword”# Search for identity file change eventssudo ausearch -k identity
# Search for privilege escalation eventssudo ausearch -k privilege_escalationSearch by Time Range
Section titled “Search by Time Range”# Search for today's eventssudo ausearch -k identity -ts today
# Search for events in the last hoursudo ausearch -k identity -ts recent
# Search a specific time rangesudo ausearch -ts 03/24/2026 09:00:00 -te 03/24/2026 18:00:00Search by User
Section titled “Search by User”# Search for a specific user's actionssudo ausearch -ua 1000
# Search for root user's actionssudo ausearch -ua 0Search by Event Type
Section titled “Search by Event Type”# Search for login eventssudo ausearch -m USER_LOGIN
# Search for authentication eventssudo ausearch -m USER_AUTH
# Search for system call eventssudo ausearch -m SYSCALL -k file_deletionInterpret Audit Logs
Section titled “Interpret Audit Logs”# Output in human-readable formatsudo ausearch -k identity -iThe -i flag converts UIDs, GIDs, system call numbers, and more into human-readable names.
Search Access Records for a Specific File
Section titled “Search Access Records for a Specific File”sudo ausearch -f /etc/passwdsudo ausearch -f /etc/shadow -iGenerating Reports with aureport
Section titled “Generating Reports with aureport”aureport generates various audit statistical reports.
Generate a Summary Report
Section titled “Generate a Summary Report”sudo aureport --summaryCommon Report Types
Section titled “Common Report Types”# Authentication reportsudo aureport -au
# Login reportsudo aureport -l
# Failed authentication reportsudo aureport -au --failed
# File access reportsudo aureport -f
# Executable file reportsudo aureport -x
# User reportsudo aureport -u
# System call reportsudo aureport -s
# Anomaly reportsudo aureport --anomaly
# Report by keywordsudo aureport -kTime-Scoped Reports
Section titled “Time-Scoped Reports”sudo aureport -au -ts todaysudo aureport -l -ts 03/24/2026 09:00:00 -te 03/24/2026 18:00:00Combining ausearch and aureport
Section titled “Combining ausearch and aureport”You can pipe ausearch results into aureport:
# View today's failed login detailssudo ausearch -m USER_LOGIN --failed -ts today | aureport -l
# View file access statistics for a specific keywordsudo ausearch -k identity | aureport -f --summaryauditd Configuration File
Section titled “auditd Configuration File”/etc/audit/auditd.conf Core Configuration
Section titled “/etc/audit/auditd.conf Core Configuration”sudo vi /etc/audit/auditd.confKey parameters:
# Log file pathlog_file = /var/log/audit/audit.log
# Log format (RAW or ENRICHED)log_format = ENRICHED
# Maximum size of a single log file (MB)max_log_file = 50
# Action when max size is reached (ROTATE, SYSLOG, SUSPEND, KEEP_LOGS)max_log_file_action = ROTATE
# Number of log files to retainnum_logs = 10
# Actions when disk space is lowspace_left = 75space_left_action = SYSLOGadmin_space_left = 50admin_space_left_action = SUSPENDdisk_full_action = SUSPENDdisk_error_action = SUSPENDHands-On: Deploying an Audit Policy
Section titled “Hands-On: Deploying an Audit Policy”-
Confirm auditd is installed and running:
Terminal window sudo dnf install audit -ysudo systemctl enable --now auditdsudo auditctl -s -
Create an audit rules file:
Terminal window sudo tee /etc/audit/rules.d/security.rules <<'EOF'-D-b 8192-f 1# Identity file monitoring-w /etc/passwd -p wa -k identity-w /etc/shadow -p wa -k identity-w /etc/group -p wa -k identity-w /etc/sudoers -p wa -k sudoers_change-w /etc/sudoers.d/ -p wa -k sudoers_change# SSH configuration monitoring-w /etc/ssh/sshd_config -p wa -k sshd_config# Privileged command monitoring-a always,exit -F arch=b64 -S execve -F path=/usr/bin/sudo -k privilege_escalation-a always,exit -F arch=b64 -S execve -F path=/usr/bin/su -k privilege_escalation# User management command monitoring-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/useradd -k user_mgmt-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/userdel -k user_mgmt-a always,exit -F arch=b64 -S execve -F path=/usr/sbin/usermod -k user_mgmt# File deletion monitoring-a always,exit -F arch=b64 -S unlink -S unlinkat -S rename -S renameat -F auid>=1000 -F auid!=-1 -k file_deletionEOF -
Load the rules:
Terminal window sudo augenrules --loadsudo auditctl -l -
Test that auditing is working correctly:
Terminal window # Modify a monitored filesudo touch /etc/passwd# Search for the corresponding audit recordsudo ausearch -k identity -ts recent -i -
Generate daily audit reports:
Terminal window # Summary reportsudo aureport --summary -ts today# Authentication reportsudo aureport -au -ts today# Keyword reportsudo aureport -k -ts today -
Optional: Set up an automatic daily report (add a cron job):
sudo tee /etc/cron.daily/audit-report <<'EOF'#!/bin/bashaureport --summary -ts yesterday -te today > /var/log/audit/daily-report-$(date +%Y%m%d).txtaureport -au --failed -ts yesterday -te today >> /var/log/audit/daily-report-$(date +%Y%m%d).txtEOFsudo chmod +x /etc/cron.daily/audit-report
auditd is the cornerstone of Linux system security auditing. By properly configuring audit rules, you can comprehensively track critical operations on the system, providing reliable data for security incident investigation and compliance auditing.