Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #224409

No "type=APPARMOR_ALLOWED/DENIED" logs

From l0f4r0@tuta.io
Newsgroups linux.debian.user
Subject No "type=APPARMOR_ALLOWED/DENIED" logs
Date 2020-07-05 21:10 +0200
Message-ID <Apibw-2pz-9@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Hi,

I'm under Debian 10 (kernel 5.4.8-1~bpo10+1) and I installed auditd some weeks ago.
Issue: I don't get any AppArmor logs like ALLOWED or DENIED in my /var/log/audit/audit.log while I'm sure I should have some (for example, aa-genprof seems unable to scan my logs and help me to generate an appropriate profile).

I thought AppArmor writes its logs directly in /var/log/audit/audit.log if auditd is already installed, otherwise they go to /var/log/syslog, /var/log/messages or /var/log/kern.log. I have nothing there neither...
Did I miss something please?

NB:
* the only AppArmor related logs I have are some apparmor="STATUS" regarding operation="profile_load" for the most part...
* apparmor.service is running and everything is OK with aa-status

Thanks in advance :)
Best regards,
l0f4r0

Back to linux.debian.user | Previous | NextNext in thread | Find similar | Unroll thread


Thread

No "type=APPARMOR_ALLOWED/DENIED" logs l0f4r0@tuta.io - 2020-07-05 21:10 +0200
  Re: No "type=APPARMOR_ALLOWED/DENIED" logs didier.gaumet@gmail.com - 2020-07-06 12:30 +0200
    Re: No "type=APPARMOR_ALLOWED/DENIED" logs l0f4r0@tuta.io - 2020-07-06 23:10 +0200
      Re: No "type=APPARMOR_ALLOWED/DENIED" logs didier.gaumet@gmail.com - 2020-07-07 00:10 +0200
        Re: No "type=APPARMOR_ALLOWED/DENIED" logs l0f4r0@tuta.io - 2020-07-08 01:00 +0200

csiph-web