Skip to content

Commit

Permalink
Merge pull request #7381 from wazuh/change/7283-auditd-remove-never-t…
Browse files Browse the repository at this point in the history
…ask-rule

Modify note related to 'never,task' rule in auditd
  • Loading branch information
javimed authored Jun 11, 2024
2 parents f8d8a96 + c63a11b commit 94c7ce7
Showing 1 changed file with 1 addition and 7 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -75,13 +75,7 @@ In most systems, auditd includes a rule to skip processing of every audit rule b
# auditctl -l | grep task
#. If the output displays the ``-a never,task`` rule, add the following filter rule in ``/etc/audit/rules.d/audit.rules``. Make sure to place it before the mentioned rule.

.. code-block:: none
:emphasize-lines: 1
-a always,task -F exe=‘/var/ossec/bin/wazuh-syscheckd’
-a never,task
#. If the output displays the ``-a never,task`` rule, remove it from the audit rules file located at ``/etc/audit/rules.d/audit.rules``.

#. After that, restart auditd and Wazuh agent to apply the changes:

Expand Down

0 comments on commit 94c7ce7

Please sign in to comment.