audit_add_rule_data man page on Oracle

Man page or keyword search:  
man Server   33470 pages
apropos Keyword Search (all sections)
Output format
Oracle logo
[printable version]

AUDIT_ADD_RULE_DATA(3)		Linux Audit API		AUDIT_ADD_RULE_DATA(3)

NAME
       audit_add_rule_data - Add new audit rule

SYNOPSIS
       #include <libaudit.h>

       int  audit_add_rule_data	 (int  fd,  struct  audit_rule_data *rule, int
       flags, int action);

DESCRIPTION
       audit_add_rule  adds  an	 audit	rule   previously   constructed	  with
       audit_rule_fieldpair_data(3)  to	 one  of several kernel event filters.
       The filter is specified by the  flags  argument.	 Possible  values  for
       flags are:

       ·  AUDIT_FILTER_USER - Apply rule to userspace generated messages.

       ·  AUDIT_FILTER_TASK - Apply rule at task creation (not syscall).

       ·  AUDIT_FILTER_EXIT - Apply rule at syscall exit.

       ·  AUDIT_FILTER_TYPE - Apply rule at audit_log_start.

       The rule's action has two possible values:

       ·  AUDIT_NEVER - Do not build context if rule matches.

       ·  AUDIT_ALWAYS - Generate audit record if rule matches.

RETURN VALUE
       The return value is <= 0 on error, otherwise it is the netlink sequence
       id  number.  This  function  can	 have  any  error  that	 sendto	 would
       encounter.

SEE ALSO
       audit_rule_fieldpair_data(3), audit_delete_rule_data(3), auditctl(8).

AUTHOR
       Steve Grubb.

Red Hat				   Aug 2009		AUDIT_ADD_RULE_DATA(3)
[top]

List of man pages available for Oracle

Copyright (c) for man pages and the logo by the respective OS vendor.

For those who want to learn more, the polarhome community provides shell access and support.

[legal] [privacy] [GNU] [policy] [cookies] [netiquette] [sponsors] [FAQ]
Tweet
Polarhome, production since 1999.
Member of Polarhome portal.
Based on Fawad Halim's script.
....................................................................
Vote for polarhome
Free Shell Accounts :: the biggest list on the net