Linux Audit to BSM conversion

audit-userspace

audit-userspace on GitHub

Hints

Understanding a field step by step

  1. Choose your field.
  2. Find it in the field dictionary to get any idea what it is.

  3. Find out if it is listed in auparse/typetab.h to learn its type.

    You can also run grep -RI -C 2 *tab.h in auparse; your field might be listed in one of those files.

Structure

Resources

General

Log files

Structure

Linux Audit event field

Linux Audit event record

SummerOfCode2016/NonBSMtoBSMConversionTools/LinuxAuditToBSM (last edited 2016-08-08T09:06:54+0000 by MateuszPiotrowski)