Bug 2224661 - Clarification about control characters in audit.log
Summary: Clarification about control characters in audit.log
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: audit
Version: 8.8
Hardware: All
OS: Linux
unspecified
low
Target Milestone: rc
: ---
Assignee: Sergio Correia
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-21 21:09 UTC by Paulo Andrade
Modified: 2023-07-24 14:01 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-07-24 14:01:30 UTC
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-163009 0 None None None 2023-07-21 21:11:41 UTC
Red Hat Issue Tracker SECENGSP-5306 0 None None None 2023-07-21 21:09:47 UTC

Description Paulo Andrade 2023-07-21 21:09:27 UTC
The character ^], from 'man ascii':

       035   29    1D    GS  (group separator)       135   93    5D    ]

is common in /var/log/audit.log. Is there some explanation for it?

  Apparently it was not the case in 2.8.5 (rhel7), but appears common
in audit 3.0.7 or newer.

Comment 1 Steve Grubb 2023-07-24 12:44:38 UTC
Yes, the group separator is used to mark the end of the event and the beginning of interpreted data. This standard has been published for at least 7 years:

https://github.com/linux-audit/audit-documentation/wiki/SPEC-Audit-Event-Enrichment

This information is processed by the audit utilities to accurately determine user mappings when the logs are viewed on a remote system.

Comment 4 Paulo Andrade 2023-07-24 14:01:30 UTC
Thanks Steve. As you described earlier (making it clear here) if one wants
to avoid the control character, can set 'raw' to 'log_format' in
/etc/audit/auditd.conf, but that will cause the logs to not be transportable
to other systems.


Note You need to log in before you can comment on or make changes to this bug.