-
-
Notifications
You must be signed in to change notification settings - Fork 56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
hostname translated to numbers in v0.6.0 #210
Comments
hillu
added a commit
to hillu/laurel
that referenced
this issue
Mar 15, 2024
hillu
added a commit
to hillu/laurel
that referenced
this issue
Mar 15, 2024
hillu
added a commit
to hillu/laurel
that referenced
this issue
Mar 15, 2024
Good catch! I suppose this warrants a bugfix release. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
auditd version: audit-3.0.7-104.el9.x86_64
laurel version: v0.6.0
os version: rocky linux 9.3
I've set name_format to hostname in auditd.conf and I can see my hostname 'purpleteam-rocky' is added to the auditd logs. When I checked laurel instead of the hostname I found the 'NODE' key to contain 16 digits instead of my hostname (which is also 16 characters).
I've tried running laurel v0.5.6 instead of v0.6.0 and it works for that version so it appears that something was changed in the latest release.
Here's a snippet when running laurel v0.5.6:
And this is v0.6.0:
And for reference a snippet of the actual auditd log:
I've tried doing the translating in laurel instead of using 'log_format = ENRICHED' but that doesn't make any difference.
The text was updated successfully, but these errors were encountered: