AUSEARCH(8) (System Administration Utilities) (NAME) ausearch - (SYNOPSIS) ausearch [options] (DESCRIPTION) ausearch (audit daemon) . ausearch (stdin) . <<>> (AND) . -m -ui (user id) . -m -n (node) . (syscall) () (event ID) . . . <> PATH . ausearch . SYSCALL . . PATH (hostname) (loginuid) . (OPTIONS) -a, --event audit-event-id (event ID) . msg=audit(1116360555.329:2401771) . <<:>> . . . . --arch CPU (CPU) . b32 . b64. . 'uname -m' . -c, --comm comm-name comm . comm (task structure) . --debug (malformed) (stderr). --checkpoint checkpoint-file (checkpoint) ausearch . auditd . ausearch (complete) (in-complete) . . inode checkpoint-file . ausearch . . ausearch . (EXIT STATUS) . --eoe-timeout seconds (end of event). end_of_event_timeout auditd.conf(5) . /etc/auditd/auditd.conf . -e, --exit exit-code-or-errno errno . --escape option (escape) . : raw tty shell shell_quote. shell tty . tty . --extra-keys format csv (key) . SYSCALL . --extra-labels format csv (subject) (object) . --extra-obj2 format csv . . (mount) . --extra-time format csv . -f, --file file-name . af_unix . --format option . : raw default interpret csv text. raw --raw . default . interpret -i . csv (CSV) . text . . -ga, --gid-all all-group-id . -ge, --gid-effective effective-group-id . -gi, --gid group-id . -h, --help . -hn, --host host-name . (FQDN) . . addr host . --node node . -i, --interpret . uid . (unenriched) . . (enriched) . . -if, --input file-name | directory . . . --input-logs auditd.conf . ausearch cron job . --just-one . -k, --key key-string . -l, --line-buffered . (pipe) . . -m, --message message-type | comma-sep-message-type-list . ( .) -m . ALL . . . . (space) . -n, --node node-name . . node . --host (audit trail) . -o, --object SE-Linux-context-string tcontext (/) . -p, --pid process-id . -pp, --ppid parent-process-id . -r, --raw . . -sc, --syscall syscall-name-or-value (syscall) . syscall . syscall . -se, --context SE-Linux-context-string scontext/ tcontext/ . --session Login-Session-ID . . -su, --subject SE-Linux-context-string scontext () . -sv, --success success-value . yes no. -te, --end [end-date] [end-time] . (locale) . date '+%x' . today . now . AM PM . en_US.utf8 09/03/2009 . 18:00:00 . LC_TIME . : now recent this-hour boot today yesterday this-week week-ago this-month this-year. Now . Recent . Boot . Today . Yesterday . This-week ( localtime ). Week-ago . This-month . This-year . -ts, --start [start-date] [start-time] . (locale) . date '+%x' . today . midnight . AM PM . en_US.utf8 09/03/2009 . 18:00:00 . LC_TIME . : now recent this-hour boot today yesterday this-week week-ago this-month this-year checkpoint. Boot . Today . Recent . Yesterday . This-week ( localtime ). Week-ago . This-month . This-year . checkpoint ausearch inode . ausearch checkpoint . : ausearch --checkpoint /etc/audit/auditd_checkpoint.txt -i _au_status=$? if test ${_au_status} -eq 10 -o ${_au_status} -eq 11 -o ${_au_status} -eq 12 then ausearch --checkpoint /etc/audit/auditd_checkpoint.txt --start checkpoint -i fi -tm, --terminal terminal . cron atd . -ua, --uid-all all-user-id (auid) . -ue, --uid-effective effective-user-id . -ui, --uid user-id . -ul, --loginuid login-id . PAM (PAMified) pam_loginuid (required) loginuid (auid) . -uu, --uuid guest-uuid (guest UUID) . -v, --version . -vm, --vm-name guest-name (guest name) . -w, --word . : filename hostname terminal keys SELinux. -x, --executable executable . (EXIT STATUS) 0 (OK). 1 / . 10 checkpoint . 11 (checkpoint). 12 . (NOTE) (boot time) . /proc/uptime . ( ntp) . . : date -d "`cut -f1 -d. /proc/uptime` seconds ago" (EXAMPLES) : # ausearch --start today --loginuid john -i SELinux (denial) : # ausearch --start today -m avc -i SELinux: # ausearch -m avc,user_avc,selinux_err,user_selinux_err -i -ts recent : # ausearch --start today --format text TTY : # ausearch --start today -m TTY -i --escape shell_quote (SEE ALSO) auditd(8), auditd.conf(5), aureport(8), pam_loginuid(8). Red Hat AUSEARCH(8)