Skip to content

Auditd Setup

Linux systems rely on the auditd daemon (part of the Linux Audit Framework) to monitor and record security-related events, such as system calls, file accesses, and process executions. Proper configuration of auditd is critical for detecting unauthorized activities, enforcing security policies, and ensuring compliance. This section explains how to set up and manage auditd for robust security auditing.


Installing and Configuring auditd

Ensure auditd is installed and running. Most Linux distributions include it by default, but you may need to install it explicitly:

# RHEL/CentOS
sudo yum install audit
# Debian/Ubuntu
sudo apt install auditd

Verify the service status:

sudo systemctl status auditd

Configure auditd via /etc/audit/auditd.conf. Key parameters include: - log_file: Path to the audit log (default: /var/log/audit/audit.log). - log_format: Set to csv for structured logging. - max_log_file: Maximum size of a single log file (e.g., 10M). - space_left: Threshold for disk space before log rotation (e.g., 10%). - flush: Set to 1 to ensure logs are written immediately.

Example configuration snippet:

log_file = /var/log/audit/audit.log
log_format = csv
max_log_file = 10M
space_left = 10
flush = 1

Restart the service after changes:

sudo systemctl restart auditd


Setting Up Audit Rules

Audit rules define what events to monitor. Edit /etc/audit/audit.rules to add rules. Use auditctl to apply rules dynamically.

Example Rules

  1. Track file access to sensitive paths:

    sudo auditctl -w /etc/passwd -p rwa -k passwd_access
    sudo auditctl -w /etc/shadow -p rwa -k shadow_access
    
    This monitors read/write/execute operations on /etc/passwd and /etc/shadow.

  2. Audit system calls:

    sudo auditctl -a -s
    
    This enables auditing of all system calls (use with caution for performance).

  3. Enforce rules:

    sudo auditctl -e 2
    
    Sets enforcement level 2 (enforce rules strictly).

To list active rules:

sudo auditctl -l


Monitoring and Analyzing Logs

Audit logs are stored in /var/log/audit/audit.log (or rotated to audit.log.1, audit.log.2, etc.). Use tools like ausearch and aureport to query logs:

# Search for events related to file access
sudo ausearch -k passwd_access

# Generate a summary report
sudo aureport -a

For real-time monitoring:

sudo ausearch -f /etc/passwd


Best Practices for Security Auditing

  • Limit rule scope: Avoid auditing all system calls to prevent performance degradation.
  • Secure log storage: Ensure /var/log/audit/ is readable only by root and protected from tampering.
  • Rotate logs regularly: Use logrotate to manage log file sizes and prevent disk exhaustion.
  • Centralize logs: Forward logs to a SIEM (Security Information and Event Management) system for centralized analysis.
  • Test rules in staging: Validate rules in a non-production environment before deployment.

Key takeaways

  • Configure auditd to track critical system calls and file accesses using /etc/audit/audit.rules.
  • Use auditctl to dynamically manage rules and enforce security policies.
  • Leverage ausearch and aureport for efficient log analysis and incident detection.
  • Secure audit logs and rotate them regularly to ensure long-term visibility and compliance.
  • Balance granularity with performance to avoid overwhelming the system with unnecessary audits.