mirror of
https://github.com/hardenedlinux/harbian-audit.git
synced 2025-07-31 01:24:58 +02:00
Merge pull request #29 from Samson-W/master
Fix a bug and update how_to_deploy_audisp_remote_for_audit_log.mkd
This commit is contained in:
commit
8995b0c9db
@ -50,6 +50,12 @@ If not record logs on local filesystem, Modify /etc/audit/auditd.conf:
|
||||
write_logs = no
|
||||
```
|
||||
|
||||
Set name_format of /etc/audisp/audispd.conf to NUMERIC, in audit.log, the node will record the IP address:
|
||||
```
|
||||
name_format = NUMERIC
|
||||
```
|
||||
** Note: The IP address may be 127.0.1.1, please modify it in /etc/hosts. You can use hostname -i to check whether it is the correct address. **
|
||||
|
||||
### Restart service
|
||||
Restart auditd service:
|
||||
```
|
||||
|
@ -459,7 +459,7 @@ is_kernel_option_enabled() {
|
||||
is_a_partition() {
|
||||
local PARTITION=$1
|
||||
FNRET=128
|
||||
if $(grep "[[:space:]]*${PARTITION}[[:space:]]*" /etc/fstab | grep -vqE "^#"); then
|
||||
if $(grep "[[:space:]]*${PARTITION}[[:space:]].*" /etc/fstab | grep -vqE "^#"); then
|
||||
debug "$PARTITION found in fstab"
|
||||
FNRET=0
|
||||
else
|
||||
|
Loading…
x
Reference in New Issue
Block a user