Auditd Setup
Linux systems rely on the auditd daemon (part of the Linux Audit Framework) to monitor and record security-related events, such as system calls, file accesses, and process executions. Proper configuration of auditd is critical for detecting unauthorized activities, enforcing security policies, and ensuring compliance. This section explains how to set up and manage auditd for robust security auditing.
Installing and Configuring auditd¶
Ensure auditd is installed and running. Most Linux distributions include it by default, but you may need to install it explicitly:
Verify the service status:
Configure auditd via /etc/audit/auditd.conf. Key parameters include:
- log_file: Path to the audit log (default: /var/log/audit/audit.log).
- log_format: Set to csv for structured logging.
- max_log_file: Maximum size of a single log file (e.g., 10M).
- space_left: Threshold for disk space before log rotation (e.g., 10%).
- flush: Set to 1 to ensure logs are written immediately.
Example configuration snippet:
Restart the service after changes:
Setting Up Audit Rules¶
Audit rules define what events to monitor. Edit /etc/audit/audit.rules to add rules. Use auditctl to apply rules dynamically.
Example Rules¶
-
Track file access to sensitive paths:
This monitors read/write/execute operations onsudo auditctl -w /etc/passwd -p rwa -k passwd_access sudo auditctl -w /etc/shadow -p rwa -k shadow_access/etc/passwdand/etc/shadow. -
Audit system calls:
This enables auditing of all system calls (use with caution for performance). -
Enforce rules:
Sets enforcement level2(enforce rules strictly).
To list active rules:
Monitoring and Analyzing Logs¶
Audit logs are stored in /var/log/audit/audit.log (or rotated to audit.log.1, audit.log.2, etc.). Use tools like ausearch and aureport to query logs:
# Search for events related to file access
sudo ausearch -k passwd_access
# Generate a summary report
sudo aureport -a
For real-time monitoring:
Best Practices for Security Auditing¶
- Limit rule scope: Avoid auditing all system calls to prevent performance degradation.
- Secure log storage: Ensure
/var/log/audit/is readable only byrootand protected from tampering. - Rotate logs regularly: Use
logrotateto manage log file sizes and prevent disk exhaustion. - Centralize logs: Forward logs to a SIEM (Security Information and Event Management) system for centralized analysis.
- Test rules in staging: Validate rules in a non-production environment before deployment.
Key takeaways¶
- Configure
auditdto track critical system calls and file accesses using/etc/audit/audit.rules. - Use
auditctlto dynamically manage rules and enforce security policies. - Leverage
ausearchandaureportfor efficient log analysis and incident detection. - Secure audit logs and rotate them regularly to ensure long-term visibility and compliance.
- Balance granularity with performance to avoid overwhelming the system with unnecessary audits.