Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[auditd] Collect ausearch with more human readable output #3461

Merged

Conversation

pmoravec
Copy link
Contributor

@pmoravec pmoravec commented Jan 4, 2024

ausearch sometimes outputs hexstream instead of raw text esp for "proctitle" values. Let collect more human readable output.

Resolves: #3461
Related: RHEL-19434


Please place an 'X' inside each '[]' to confirm you adhere to our Contributor Guidelines

  • Is the commit message split over multiple lines and hard-wrapped at 72 characters?
  • Is the subject and message clear and concise?
  • Does the subject start with [plugin_name] if submitting a plugin patch or a [section_name] if part of the core sosreport code?
  • Does the commit contain a Signed-off-by: First Lastname [email protected]?
  • Are any related Issues or existing PRs properly referenced via a Closes (Issue) or Resolved (PR) line?

ausearch sometimes outputs hexstream instead of raw text esp for
"proctitle" values. Let collect more human readable output.

Resolves: sosreport#3461

Signed-off-by: Pavel Moravec <[email protected]>
@pmoravec
Copy link
Contributor Author

pmoravec commented Jan 4, 2024

Currently collected output:

proctitle=2F7573722F6C6962657865632F737373642F737373645F6265002D2D646F6D61696E006C646170002D2D7569640030002D2D6769640030002D2D6C6F676765723D66696C6573

Newly collected output:

proctitle=/usr/libexec/sssd/sssd_be --domain ldap --uid 0 --gid 0 --logger=files

Copy link

Congratulations! One of the builds has completed. 🍾

You can install the built RPMs by following these steps:

  • sudo yum install -y dnf-plugins-core on RHEL 8
  • sudo dnf install -y dnf-plugins-core on Fedora
  • dnf copr enable packit/sosreport-sos-3461
  • And now you can install the packages.

Please note that the RPMs should be used only in a testing environment.

@TurboTurtle TurboTurtle merged commit 96bbdc5 into sosreport:main Jan 5, 2024
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants