diff --git a/Auditd/decoders/auditd-path.xml b/Auditd/decoders/auditd-path.xml new file mode 100644 index 0000000..21ad6ec --- /dev/null +++ b/Auditd/decoders/auditd-path.xml @@ -0,0 +1,20 @@ + + ^type=PATH + + + + + + auditd-path + + msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): item=\S+ name="(\.*)" inode=(\S+) dev=\S+ mode=(\S+) ouid=\S+ ogid=\S+ rdev=\S+ nametype=(\S+) + audit.id,audit.directory.name, audit.directory.inode, audit.directory.mode,audit.directory.nametype + + + + auditd-path + type=PATH msg=audit\(\S+\): item=\S+ name="(\.*)" inode=(\S+) dev=\S+ mode=(\S+) ouid=\S+ ogid=\S+ |type=PATH msg=audit\(\S+\): item=\S+ name=\((null)\) inode=(\S+) dev=\S+ mode=(\S+) ouid=\S+ ogid=\S+ + audit.file.name, audit.file.inode, audit.file.mode +