<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Audit.log in linux capturing SAS audit in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Audit-log-in-linux-capturing-SAS-audit/m-p/697082#M20635</link>
    <description>&lt;P&gt;All,&lt;/P&gt;
&lt;P&gt;Audit.log in Linux is capturing the SAS details. is it by default or do we need to configure it somewhere?&lt;/P&gt;
&lt;P&gt;Audit log is filling up very fast after patching that is causing server crash.Log rotation in place but not working after patching.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;type=PROCTITLE msg=audit(1604652864.918:12790651): proctitle=706F7374677265733A20737461747320636F6C6C6563746F722070726F63657373202020&lt;BR /&gt;type=SYSCALL msg=audit(1604652864.918:12790652): arch=c000003e syscall=82 success=yes exit=0 a0=7ffd250bd920 a1=7ffd250bd520 a2=1a7a720 a3=1 items=5 ppid=26975 pid=26982 auid=1334035802 uid=103 gid=101 euid=103 suid=103 fsuid=103 egid=101 sgid=101 fsgid=101 tty=(none) ses=8 comm="postgres" exe="/sas/home/SASWebInfrastructurePlatformDataServer/9.4/bin/postgres" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="delete"&lt;BR /&gt;type=CWD msg=audit(1604652864.918:12790652): cwd="/SAS/config/Lev2/WebInfrastructurePlatformDataServer/data"&lt;BR /&gt;type=PATH msg=audit(1604652864.918:12790652): item=0 name="pg_stat_tmp/" inode=1575695 dev=ca:a0 mode=040700 ouid=103 ogid=101 rdev=00:00 obj=unconfined_u:object_r:unlabeled_t:s0 objtype=PARENT cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 09:31:46 GMT</pubDate>
    <dc:creator>sathya66</dc:creator>
    <dc:date>2020-11-06T09:31:46Z</dc:date>
    <item>
      <title>Audit.log in linux capturing SAS audit</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Audit-log-in-linux-capturing-SAS-audit/m-p/697082#M20635</link>
      <description>&lt;P&gt;All,&lt;/P&gt;
&lt;P&gt;Audit.log in Linux is capturing the SAS details. is it by default or do we need to configure it somewhere?&lt;/P&gt;
&lt;P&gt;Audit log is filling up very fast after patching that is causing server crash.Log rotation in place but not working after patching.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;type=PROCTITLE msg=audit(1604652864.918:12790651): proctitle=706F7374677265733A20737461747320636F6C6C6563746F722070726F63657373202020&lt;BR /&gt;type=SYSCALL msg=audit(1604652864.918:12790652): arch=c000003e syscall=82 success=yes exit=0 a0=7ffd250bd920 a1=7ffd250bd520 a2=1a7a720 a3=1 items=5 ppid=26975 pid=26982 auid=1334035802 uid=103 gid=101 euid=103 suid=103 fsuid=103 egid=101 sgid=101 fsgid=101 tty=(none) ses=8 comm="postgres" exe="/sas/home/SASWebInfrastructurePlatformDataServer/9.4/bin/postgres" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key="delete"&lt;BR /&gt;type=CWD msg=audit(1604652864.918:12790652): cwd="/SAS/config/Lev2/WebInfrastructurePlatformDataServer/data"&lt;BR /&gt;type=PATH msg=audit(1604652864.918:12790652): item=0 name="pg_stat_tmp/" inode=1575695 dev=ca:a0 mode=040700 ouid=103 ogid=101 rdev=00:00 obj=unconfined_u:object_r:unlabeled_t:s0 objtype=PARENT cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 09:31:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Audit-log-in-linux-capturing-SAS-audit/m-p/697082#M20635</guid>
      <dc:creator>sathya66</dc:creator>
      <dc:date>2020-11-06T09:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Audit.log in linux capturing SAS audit</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Audit-log-in-linux-capturing-SAS-audit/m-p/697083#M20636</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/93352"&gt;@sathya66&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't think its enabled by default. You can check the audit rules under /etc/audit/audit.rules or /etc/audit/rules.d/audit.rules file.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 09:37:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Audit-log-in-linux-capturing-SAS-audit/m-p/697083#M20636</guid>
      <dc:creator>AnandVyas</dc:creator>
      <dc:date>2020-11-06T09:37:10Z</dc:date>
    </item>
  </channel>
</rss>

