Skip to content

Glossary

auditd

The Linux audit daemon, which writes kernel audit records (logins, sessions, executed programs, watched files) to /var/log/audit/audit.log.

auditd is the user-space daemon of the Linux audit framework. The kernel audit subsystem generates records for events selected by rules (system calls, file watches) and for user-space events reported by PAM, sudo, passwd and similar tools; auditd writes them to /var/log/audit/audit.log. It rotates the file itself according to /etc/audit/auditd.conf (max_log_file and num_logs, by default five files of 8 MiB) rather than through logrotate.

Rules live in /etc/audit/rules.d/*.rules and are loaded at boot; auditctl -l shows the rules actually loaded. auditd is installed and enabled by default on RHEL and Fedora, not on Debian or Ubuntu.

Why it matters in investigations

audit.log is fed by the kernel, not by syslog, so it is an independent source next to auth.log and the journal. Without any custom rule it still records PAM logins and sessions (USER_AUTH, USER_LOGIN, USER_START, USER_END), sudo commands (USER_CMD), password changes (USER_CHAUTHTOK) and account creation (ADD_USER). With an execve rule it records every program run, including inside a root shell where auth.log is blind. Every record carries the login UID and session ID of the process. Audit tampering is visible too: CONFIG_CHANGE records, auditctl -D or auditctl -e 0, and auditd.service stopping outside a reboot.

Example

A typical execve rule and a query on a collected log:

-a always,exit -F arch=b64 -S execve -k exec
ausearch -if audit.log -m USER_CMD -i          # sudo commands, decoded
ausearch -if audit.log --session 114 -i        # one login session

Read the rules on the image before concluding anything from missing execve records.

Linux Log Parser reads RAW and ENRICHED audit.log in the browser. Details: auditd EXECVE forensics.