AUDISP-FILTER(8) (System Administration Utilities) (NAME) audisp-filter - audispd (SYNOPSIS) audisp-filter MODE CONFIG_FILE BINARY [ BINARY_ARGS ] (DESCRIPTION) audisp-filter (audit event dispatcher) . () . . : MODE allowlist blocklist . : allowlist ausearch (drop) . blocklist ausearch (drop) . / . CONFIG_FILE ausearch. BINARY . BINARY_ARGS . (CONFIGURATION AND RULES EVALUATION) . (audit config directory) audisp-filter-pluginname.conf : audisp-filter-syslog.conf syslog. ausearch-expression(5) . OR . (PE || CE) PE CE . '#' () . . . : audisp-filter . (event based) (record based). . () . (EXAMPLES) : openat syslog. allowlist /sbin/audisp-syslog . . () . audisp-filter --check path/to/config/file : (type r= SYSCALL && syscall i= openat && success r= no) : SERVICE_STOP NETFILTER_CFG . blocklist : type r= SERVICE_STOP type r= NETFILTER_CFG NETFILTER_CFG SYSCALL PROCTITLE . NETFILTER_CFG audisp-filter . SERVICE_START . (FILES) /etc/audit/plugins/filter.conf /etc/audit/auditd.conf (SEE ALSO) auditd.conf(8), ausearch-expression(5), auditd-plugins(5). (AUTHOR) Attila Lakatos Red Hat AUDISP-FILTER(8)