problem of setting audit rules: Syscall name unknown: stime

Posted by zhaojing on Server Fault See other posts from Server Fault or by zhaojing
Published on 2010-09-10T05:09:13Z Indexed on 2011/02/09 23:27 UTC
Read the original article Hit count: 1305

Filed under:
|
|
|

I am setting audit rules in /etc/audit/audit.rules.

As the requirement : The audit system should be configured to audit all administrative, privileged, and security actions.

So I add one line into /etc/audit/auditd.rules:

-a exit,always -S stime -S acct -S reboot -S swapon

However, after I restart audit.d by service auditd restart:

There is error comeout:
Stopping auditd:                                           [  OK  ]
Starting auditd:                                           [  OK  ]
Syscall name unknown: stime
There was an error in line 14 of /etc/audit/audit.rules

It seems stime can't be recognized. Could anybody help me to find out what is wrong with my added rule? Thanks a lot!

© Server Fault or respective owner

Related posts about redhat

Related posts about audit