Prev Question
Next Question

You administer a system which has BSM enabled. You just added an extra audit-class to the flag: entry in /etc/security/audit_control, and you executed audit -s. Now you want to validate that this extra class is audited correctly, so you execute a command that should generate an audit record. Unfortunately, nothing appears in the audit log because the audit pre-selection mask is not yet in effect.

What do you minimally need to do to get the pre-selection mask in effect for your test?


restart auditd

execute audit -n

start a new login session

Prev Question
Next Question

Leave a Reply

Your email address will not be published. Required fields are marked *