auditd on builders #50

Open
opened 2024-07-09 23:19:40 +00:00 by raito · 2 comments
raito commented 2024-07-09 23:19:40 +00:00 (Migrated from git.lix.systems)

(Low priority)

Figuring out a simple auditd configuration for builders and ship it to meta01 or similar for further review/forensics would be great.

**(Low priority)** Figuring out a **simple** auditd configuration for builders and ship it to meta01 or similar for further review/forensics would be great.
emilylange commented 2024-07-10 12:05:47 +00:00 (Migrated from git.lix.systems)

Plain auditd, or something much nicer and easier to read and still fairly simple like https://github.com/threathunters-io/laurel?

We could collect laurel's json logs via Grafana Agent and sent them to Loki.

Plain auditd, or something much nicer and easier to read and still fairly simple like https://github.com/threathunters-io/laurel? We could collect laurel's json logs via Grafana Agent and sent them to Loki.
raito commented 2024-07-10 13:16:12 +00:00 (Migrated from git.lix.systems)

I would go for Laurel personally, yes.

I would go for Laurel personally, yes.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: afnix/infra#50
No description provided.