AUDITD.CONF(5) (NAME) auditd.conf - (audit daemon) (DESCRIPTION) /etc/audit/auditd.conf (auditd) . (=) . (case-insensitive). . . () '#' . local_events yes/no . yes . no . . . log_file . (regular file) . /var/log/audit/audit.log . write_logs yes/no . yes . log_format . : raw enriched. RAW . ENRICHED uid gid (syscall) (resolve) . . NOLOG . write_logs no . log_group . root . . priority_boost . . . flush : none incremental incremental_async data sync. none . incremental freq . incremental_async incremental . data (sync) . sync (meta-data) . incremental_async . freq . flush incremental incremental_async . num_logs rotate max_log_file_action . (rotate) . . . (kernel backlog) . /etc/audit/audit.rules . . . name_format (node) . : none hostname fqd numeric user. none . hostname gethostname . fqd DNS (FQDN) . numeric fqd IP . 'hostname -i' 'domainname -i' . DHCP . user name . none . name user name_format . max_log_file (MiB) . . . max_log_file_action . : ignore syslog exec suspend rotate keep_logs. ignore . syslog syslog . exec (/path-to-script) . . auditd . auditdctl --signal resume . . . /var/log/audit/audit.log . . suspend . rotate . . logrotate . keep_logs rotate num_logs . . - space_left_action . . verify_email action_mail_acct (resolve) . action_mail_acct yes . action_mail_acct (alias) . RFC 5233 '+' . '@' '.' '-' '_' '+' . root . . /usr/lib/sendmail . (symlink) . space_left log_file space_left_action . space_left (MiB) . ( 5%) log_file . ( log_file space_left 25% space_left ). log_file SIGHUP . space_left_action . : ignore syslog rotate email exec suspend single. ignore . syslog syslog . rotate . Email action_mail_acct syslog . exec (/path-to-script) . . auditd service auditd resume ( auditdctl --signal resume) . suspend . . single (single-user mode) . rotate . halt . . : space_left_action (low water mark) . . admin_space_left_action . . disk_full_action . . admin_space_left (MiB) . . space_left . ( 1%) . admin_space_left_action . : ignore syslog rotate email exec suspend single halt. ignore . Syslog syslog . rotate . Email action_mail_acct syslog . exec . . service auditd resume . Suspend . single . halt . rotate . disk_full_action . : ignore syslog rotate exec suspend single halt. ignore syslog . Syslog syslog . rotate . exec . . service auditd resume . Suspend . single . halt . disk_error_action . : ignore syslog exec suspend single halt. ignore . Syslog syslog . exec . . Suspend . single . halt . tcp_listen_port auditd TCP . tcp_wrappers (link) hosts.allow hosts.deny . systemd 'After' auditd.service . SIGHUP auditd . . tcp_listen_queue ( ) . . ( ) . . . tcp_max_per_addr IP . . (DoS) . auditd . . use_libwrap tcp_wrappers . yes no . yes . tcp_client_ports ( ). . . . (privileged) 1-1023 . local_port audisp-remote.conf . . tcp_client_max_idle ( ) auditd . . heartbeat_timeout ( ). . transport TCP TCP . TLS TLS 1.3 - (post- quantum hybrid key exchange) . (tls_psk_file) . KRB5 Kerberos 5 . TCP . . enable_krb5 transport . "yes" Kerberos 5 . "no" . "yes" transport transport . . krb5_principal (principal) . "auditd" . auditd/hostname@EXAMPLE.COM /etc/audit/audit.key hostname (canonical) DNS IP . krb5_key_file . root 0400 . /etc/audit/audit.key . tls_auth TLS. psk ( / Pre-Shared Key) . psk . tls_crypto_profile (cryptographic profile) TLS . : compatible system pqc. compatible TLS 1.3 PSK - (PQC) (opportunistic) . system (system crypto policy) . FIPS FIPS . pqc - . compatible . tls_psk_file TLS-PSK. ( ) . openssl rand -hex 32 . root 0400 . tls_allowed_clients ( ) . tls_psk_identity (identity) PSK. tls_psk_file tls_allowed_clients . . ( ) . tls_allowed_clients PSK . : (identity) (enabled disabled) . # () . Single-PSK ( ): tls_psk_file . enabled . PSK (rotate) . # identity status notes host-1234 enabled prod web host host-5678 disabled retired (Per-identity key mode): key= . . key= / ( ) . tls_psk_file ( 0400 root ). key= . . # identity status key file host-prod enabled key=/etc/audit/psk/host-prod.key host-retired disabled key=/etc/audit/psk/host-retired.key tls_psk_file . . PSK tls_psk_identity . root . . SIGHUP (ACL) ACL . AUDIT_DAEMON_CLOSE AUDIT_CRYPTO_KEY_USER . tls_cipher_suites (cipher suites) TLS 1.3 (:) . . "TLS_AES_128_GCM_SHA256: TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384" . tls_key_exchange . . PQC . PQC (DPI) . tls_require_pqc tls_crypto_profile=pqc . yes tls_crypto_profile pqc . no tls_crypto_profile ( ). tls_crypto_profile . distribute_network "yes" . "no" . q_depth . . syslog (drop ) . . overflow_action . . . : ignore syslog suspend single halt. ignore . syslog syslog . suspend . single . halt . max_restarts (crashed) . . plugin_dir auditd . /etc/audit/plugins.d . end_of_event_timeout auparse() aureport(8) ausearch(8) . end_of_event_timeout . . <<>> . report_interval . m h d M . . . auditd /run/audit/auditd.state . (RELOADING) SIGHUP auditd . auditctl --signal reload . local_events verify_email . (NOTES) TLS ( tls_psk_file tls_psk_identity tls_cipher_suites tls_key_exchange tls_require_pqc tls_auth tls_crypto_profile) . tls_allowed_clients single-PSK . tls_allowed_clients SIGHUP . CAPP ( ) (audit trail) . /var/log/audit . . flush sync data . max_log_file num_logs . . max_log_file_action keep_logs . space_left . aureport -t . space_left . space_left_action email . SNMP trap exec . admin_space_left . admin_space_left_action single . disk_full_action . . single halt . disk_error_action syslog single halt . TIME_WAIT . auditd . auditd (atomic) : event0_record0 event1_record0 event2_record0 event1_record3 event2_record1 event1_record4 event3_record0 auditd . << >> (List of List LOL) . : = AUDIT_EOE ( ) = AUDIT_PROCTITLE ( AUDIT_PROCTITLE ) = AUDIT_KERNEL ( ) < AUDIT_FIRST_EVENT ( ) >= AUDIT_FIRST_ANOM_MSG ( ) >= AUDIT_MAC_UNLBL_ALLOW && <= AUDIT_MAC_CALIPSO_DEL ( ) end_of_event_timeout . (LOG ROTATION POLICY) auditd . ( ) auditd.cron(5) . (FILES) /etc/audit/auditd.conf (SEE ALSO) auditd(8) audisp-remote.conf(5) auditd-plugins(5) auditd.cron(5). (AUTHOR) Steve Grubb Red Hat 2025-06-01 AUDITD.CONF(5)