New posts in auditd

What is the syslog facility for auditd logs?

Auditd multi-line log format

selinux audit rule not logging anything

Email alert when private keys read from disk (honeypot, auditd)

Tracking file deletion using auditd without unlink?

pam_tty_audit and non privileged users

How to stop journalctl showing audit logs and only keep them in file?

How to tell if auditd has suspended logging?

Getting auditd to record the original user

How to configure Auditd to see directory name change?

Disable cron messages in auditd

Why can't I run ausearch (part of auditd) remotely over SSH?

How to enable systemd's journal audit transport?

Centos 6.5 auditd fails to start with service or /etc/init.d/audit start

What's the difference between auid, uid, euid, suid, fsuid, obj_uid, gid, egid, sgid, fsgid, obj_gid in `auditctl`?

How to install `aide` without `aide-common` in debian?

Log execve's, along with parent process argv?

auditd execve arguments that looks like encoded data

CentOS doesn't boot with "A stop job is running for Security Auditing Service" message

How to log execution of a specific binary/script using auditd or other