Enable auditing of processes that start prior to auditd
This document (7021457) is provided subject to the disclaimer at the end of this document.
SUSE Linux Enterprise Server 12 Service Pack 2 (SLES 12 SP2)
However, the processes launched prior to the audit process will not have auditing enabled when they are spawned.
The change can be implemented the following way :
- Open the file /etc/default/grub
- Append "audit=1" to the space-separated list of options specified in the GRUB_CMDLINE_LINUX_DEFAULT variable.
- Save the file
- Update the GRUB2 boot loader configuration in /boot/grub2/grub.cfg by executing
# grub2-mkconfig -o /boot/grub2/grub.cfg
- Reboot the system
- Verify that the setting is present in the /proc/cmdline file
This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7021457
- Creation Date: 18-Sep-2017
- Modified Date:03-Mar-2020
- SUSE Linux Enterprise Server
For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com