auditd is the userspace daemon for the Linux kernel's audit subsystem: real-time, syscall-level logging of security-relevant events — who read/wrote/executed what, configuration changes, authentication events, and arbitrary custom watch rules. Unlike AIDE/Tripwire, which detect that a file changed on the next scheduled check, auditd logs the event as it happens, including which process and user did it.
Install and enable¶
sudo dnf install audit # often preinstalled on RHEL family
sudo apt-get install auditd audispd-plugins
sudo systemctl enable --now auditd
Rule files¶
Persistent rules live in /etc/audit/rules.d/*.rules (compiled into /etc/audit/audit.rules by augenrules on RHEL family, or written directly on Debian/Ubuntu). Load rules immediately without a reboot with auditctl, and make them persistent by also adding them to a rules file.
sudo auditctl -l # list currently loaded rules
sudo auditctl -s # audit daemon status
Watch a file or directory for changes¶
sudo auditctl -w /etc/passwd -p wa -k passwd_changes
sudo auditctl -w /etc/shadow -p wa -k shadow_changes
sudo auditctl -w /etc/ssh/sshd_config -p wa -k sshd_config_changes
-p is the permission set to watch: r read, w write, x execute, a attribute change. -k tags matching events with a searchable key.
Track a syscall¶
sudo auditctl -a always,exit -F arch=b64 -S execve -k exec_tracking # log every program execution
sudo auditctl -a always,exit -F arch=b64 -S connect -k network_connects # log outbound connect() calls
A baseline rules file (persistent)¶
# /etc/audit/rules.d/hardening.rules
-w /etc/passwd -p wa -k identity
-w /etc/group -p wa -k identity
-w /etc/shadow -p wa -k identity
-w /etc/sudoers -p wa -k privilege_escalation
-w /etc/sudoers.d/ -p wa -k privilege_escalation
-w /var/log/auth.log -p wa -k auth_log
-a always,exit -F arch=b64 -S execve -k exec_tracking
-e 2 # make the running config immutable until reboot (optional, hardened systems)
sudo augenrules --load # RHEL family: compile rules.d/*.rules into the running config
sudo systemctl restart auditd # Debian/Ubuntu: restart to pick up /etc/audit/audit.rules
The final -e 2 line locks the audit configuration against further changes until reboot — useful for compliance profiles (PCI-DSS, CIS benchmarks reference this), but it also means you cannot loosen a bad rule without rebooting, so add it only once rules are proven.
Search and report¶
sudo ausearch -k passwd_changes # events tagged with a given key
sudo ausearch -f /etc/shadow # events touching a specific file
sudo ausearch -ua alice # events by a specific user
sudo ausearch -ts today # events since midnight
sudo aureport -au # summarized authentication report
sudo aureport --summary # overview across all event types
ausearch filters raw events; aureport produces the summarized/tabular views, both reading from /var/log/audit/audit.log.
Notes¶
- Audit rules add per-syscall overhead; broad
execve/connecttracking on a busy host generates a lot of log volume — start narrow (specific files, specific syscalls) and widen deliberately. - CIS Benchmarks and most compliance frameworks (PCI-DSS, STIG) publish specific
auditdrule sets; see cisecurity.org's benchmarks as a starting reference point rather than writing rules from scratch. - Forward
audit.logoff-host (syslog/audispd, or a log pipeline) for the same reason noted under AIDE: a root-level attacker can otherwise edit local logs to cover their tracks.