Guest User

Untitled

a guest
Jan 22nd, 2019
37
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.76 KB | None | 0 0
  1. auditbeat.modules:
  2. - module: auditd
  3. audit_rules: |
  4. -a never,exit -F auid=unset -S all
  5. -a never,exit -F auid=0 -S all
  6. -a exit,always -F arch=b64 -F auid!=unset -F euid=0 -F auid!=0 -F auid>=2000 -F auid<=2099 -F auid!=4294967295 -S execve -k rootact
  7. -a exit,always -F arch=b32 -F auid!=unset -F euid=0 -F auid!=0 -F auid>=2000 -F auid<=2099 -F auid!=4294967295 -S execve -k rootact
  8. -a exit,always -F arch=b64 -F auid!=unset -F euid>=1000 -F auid!=0 -F auid>=2000 -F auid<2100 -F auid!=4294967295 -S execve -k useract
  9. -a exit,always -F arch=b32 -F auid!=unset -F euid>=1000 -F auid!=0 -F auid>=2000 -F auid<2100 -F auid!=4294967295 -S execve -k useract
  10.  
  11. setup.template.enabled: false
  12. output.elasticsearch:
  13. hosts: ["http://xyz.com:9200"]
Add Comment
Please, Sign In to add comment