Auditd

Other

Linux Audit Framework reference. auditctl rules for file watches and syscall auditing, auditd.conf configuration, ausearch log queries, aureport summaries, audit.log format, CIS/PCI-DSS compliance rules, and audit tools.

Install

openclaw skills install auditd

auditd

Linux Audit Framework reference — kernel-level security auditing.

Commands

CommandDescription
introWhat is auditd, architecture, quick start
rulesauditctl watches, syscall rules, filters
configauditd.conf settings, rotation, disk actions
searchausearch by key, time, user, file
reportaureport summaries, login, auth, file
logsaudit.log format, field meanings
complianceCIS benchmark and PCI-DSS rules
toolsauditctl, audit2allow, aulast, autrace