Sample Header Ad - 728x90

Monitoring start and stop processes

0 votes
0 answers
145 views
Im trying to monitor the start and stop of processes on a server with auditd, using the following rule
-w /usr/bin/ -p x -k T1569.002
` However, when raising an event to generate the log and searching it with ausearch, the only log it finds is the addition of the rule.
Asked by David Pérez (1 rep)
Jul 19, 2024, 09:16 PM
Last activity: Jul 23, 2024, 12:54 PM