Red Hat Bugzilla – Bug 1296194
RFE: audit the init_module syscall event
Last modified: 2016-06-02 15:42:12 EDT
Description of problem:
When the init_module syscall is audited, the main thing that we want is the module name. This is not recorded. Also when the debugfs module is loaded, we get 1000's of PATH records. We really don't want anything except the module name. Same thing with delete_module.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. add "-a always,exit -F arch=x86_64 -S init_module -F key=mod-load" to the audit rules
2. reboot the system
3. ausearch --start today -k mod-load -i | less
Closing this as we are tracking upstream RFEs on GitHub now, see links in comment #1.