Skip to content

Add Definition to Auditd susp_activity #5142

Open
@BalsamicSentry

Description

@BalsamicSentry

I'd like to suggest adding a definition field to an Auditd rule that requires specific rules to be applied.

image

image

I see that the reference and description of the rule mention that the Auditd rule is custom, but I think it would be more clear if definition was added.

This is my first issue, sorry if I do something wrong

Metadata

Metadata

Assignees

Labels

Create Pull-Requestissues that should be provided as a pull requestWork In ProgressSome changes are needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions