auditd: file access and syscall logging
Linux doesn’t write every access to /etc/shadow or every unlink call to syslog. For incident investigation and compliance this is critical. auditd solves this: the Linux Audit kernel subsystem records system calls, file access, and more.
Installation and Startup
auditd comes in the audit package available in any distribution.
After installation, start the service via systemd.
Check status and current rules:
On RHEL-based distributions with SELinux enabled, you may need to adjust policies for auditd to work with non-standard paths. Standard installation usually covers most cases.
File Monitoring: the -w Flag
The -w flag adds a watch rule for a file. By default it tracks open, read, write, truncate, chmod, and chown.
| Flag | Meaning |
|---|---|
-w | path to watch |
-p | permissions: r(read), w(write), x(execute), a(append) |
-k | keyword for searching in logs |
Verify rules:
Remove a rule by key:
Rules added via auditctl don’t survive reboots. For persistence, write rules to /etc/audit/rules.d/:
On RHEL, rules load from /etc/audit/audit.rules via the augenrules script. Same works on Debian/Ubuntu.
System Call Logging: the -S Flag
The -S flag records the specified system call for all processes or with filters.
Check available system calls with ausyscall --dump. Not all calls are available on every architecture — on x86_64 some go through the compat layer.
Excessive syscall monitoring generates massive log volume. On production servers, limit rules with filters.
Combined rule — syscall plus path:
Filtering by UID and Executable
Without filters, rules apply globally. Add conditions for targeted monitoring.
Core filter fields:
| Flag | Description | Example |
|---|---|---|
-F | field to compare | -F uid=1000 |
arch | architecture (b32/b64) | -F arch=b64 |
uid | real UID | -F uid=33 |
euid | effective UID | -F euid=0 |
exe | full path to executable | -F exe=/bin/bash |
perm | access permissions | -F perm=awx |
Combine filters into a chain via -a:
Reading Logs: ausearch
Logs live in /var/log/audit/audit.log. Binary format, read with ausearch.
Useful output formats:
For automation, use -if (input file) — read from a dump instead of the live log:
Reading Logs: aureport
aureport aggregates logs into readable reports.
Typical aureport -s output:
Quick investigation combo — summary then details:
For SIEM or ELK ingestion, convert logs to JSON or text:
auditd doesn’t require complex setup to start capturing critical events. Install the package, add a few rules with keywords, and get comfortable with ausearch and aureport for log review.