Enabling or Disabling Auditing on Linux and UNIX Computers | Delinea (2024)

After you install the agent, you can enable auditing with the dacontrol command. The dacontrol command links all shells to the cdash shell wrapper by way of NSS. When a user opens a terminal, cdash is automatically loaded instead of the user’s shell, then cdash loads the appropriate shell for the user and begins auditing the session.

You can also choose to enable video capture editing for an installation but disable it for specific computers. You disable or enable video capture auditing for a specific computer or set of computers by using group policy settings or by modifying the agent.video.capture setting. For details, see the Group Policy Guide or the Configuration and Tuning Reference Guide.

Shell or Terminal Window Auditing

To enable auditing on a Linux or UNIX computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -e option:

    dacontrol -e

  3. Run dacontrol again to verify that auditing has been enabled or run dainfo.

    For example, the output of the dacontrol command shows something like this:

    dacontrol --query

    This machine has been configured through group policy to use installation 'DefaultInstallation'

    DirectAudit NSS module: Active

    DirectAudit is not configured to audit individual commands.

    When you enable auditing, the NSS module shows as active. You can also see if auditing is enabled or not for a system in the Audit Manager console.

After you enable auditing on a Linux or UNIX computer, you can control whether the auditing of shell activity applies for all users or for selected users by using role assignments. If auditing is enabled and the agent is not running, users with an active role assignment that requires logging are not allowed to log in.

For more information about configuring and assigning roles, see the Administrator’s Guide for Linux and UNIX.

To disable auditing on a Linux or UNIX computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -d option or the --disable option:

    dacontrol -d

    dacontrol --disable

  3. Run dacontrol again to verify that auditing has been disabled or run dainfo.

    For example:

    dacontrol --query

    This machine has been configured through group policy to use installation 'DefaultInstallation'

    DirectAudit NSS module: Inactive

    DirectAudit is not configured to audit individual commands

    When you disable auditing, the NSS module shows as inactive. You can also see if auditing is enabled or not for a system in the Audit Manager console.

Linux Desktop Auditing

In addition to shell auditing, for some Linux systems you can also enable desktop auditing. When desktop auditing is enabled, the user's entire screen is continuously monitored to record all graphical interactions. More specifically, desktop auditing captures the following:

  • The application name and window title when the user switches the focus to that application. For example, if a user opens a web browser or a terminal window.
  • Changes to the application window title that currently has focus. For example, if a user opens a web browser and goes to a new web page, desktop auditing records the title of a web page.

The supported platforms for Linux desktop auditing are as follows:

  • RHEL 6, 7, and 8 with GNOME v3
  • CentOS 6, 7, and 8 with GNOME v3

Linux sessions must be running X as the primary display manager (not Wayland).

Linux desktop auditing requires shell session auditing.

To enable desktop auditing on a Linux computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -x option or the --desktop-audit option:

    dacontrol -x

    dacontrol --desktop-audit

    To enable both shell and desktop auditing at the same time, use both the -e and -x options:

    dacontrol -e -x

  3. Run dainfo to verify that desktop auditing has been enabled.

    For example, the relevant information from the dainfo command looks like this:

    Pinging adclient: adclient is available
    Daemon status: Online
    Current installation: 'DirectAudit' (configured locally)
    Current collector: test.acme.com:5063:HOST/test.acme.com@acme.com
    DirectAudit NSS module: Active
    ...DirectAudit desktop auditing: Enabled
    User (root) audited status: Yes

    When you enable auditing, the desktop auditing module shows as Enabled. You can also see if auditing is enabled or not for a system in the Audit Manager console.

To disable desktop auditing on a Linux computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -z option or the --no-desktop-audit option:

    dacontrol -z

    dacontrol --no-desktop-audit

  3. Run dainfo to verify that desktop auditing has been disabled.

    For example, the relevant information from the dainfo command looks like this:

    Pinging adclient: adclient is available
    Daemon status: Online

    Current installation: 'DirectAudit' (configured locally)
    Current collector: test.acme.com:5063:HOST/test.acme.com@acme.com
    DirectAudit NSS module: Inactive
    ...DirectAudit desktop auditing: Disabled
    User (root) audited status: No

    When you disable auditing, the desktop auditing module shows as Disabled. You can also see if auditing is enabled or not for a system in the Audit Manager console.

Enabling or Disabling Auditing on Linux and UNIX Computers | Delinea (2024)
Top Articles
These are the 14 countries with the safest banks in the world
What Are Altcoins? A Guide to Alternative Cryptocurrencies
Qbs.team Ehub.com
The 15 Best Places for Cinema in Amsterdam
High Stakes Homework With My Stepmom
„10 Jahre 9 Plätze – 9 Schätze“: Die Finalisten 2023 stehen fest - der.ORF.at
Luvhbunny
‘White Horse’ by Chris Stapleton - Lyrics & Meaning | Holler
Aes Salt Lake City Showdown
Homewav Pending Connection
Alle koopwoningen van C&R Makelaars
Elenacdavies
Smithfield Okta Login
Www Craigslist Springfield Missouri
Strange World Showtimes Near Cec - Cinema West Theatre
Cats For Free Craigslist
Knox County 24 Hour List
El Croquis 111 - MVRDV 1997-2002.pdf - PDFCOFFEE.COM
Cookie Clicker Advanced Method Unblocked
Hindi Links 4U
Un-Pc Purchase Crossword Clue
Tallahassee Forecast 10 Day
Churchill Downs Racing Entries
Tsp Paf 360
Renfield Showtimes Near Paragon Theaters - Coral Square
Thule Racks & Gear - Rack Attack
Different Types of Nameplates, Nameplate Materials & More
How to Learn Your 7 Times Table: Tips from a Teacher
Remember those moving, 3D portraits from Harry Potter? They’re a real thing now! - Yanko Design
Boolyflix
Affordable Phone Plans Starting at $15/Mo. | Connect by T-Mobile
Dollar Storw Near Me
Oppenheimer Showtimes Near B&B Theatres Liberty Cinema 12
Botw Royal Guard
The News and Herald from Winnsboro, South Carolina
Heather Mestdagh Obituary
The Ben Shapiro Show Soundcloud
Wheely 6 Abcya
Online Finance & Accounting Courses
라이키 유출
Soapzone Gh Boards
Her Triplet Alphas Chapter 26 Free
Oil Change Services | Jiffy Lube
truckoo | Gebrauchte LKW mit einem Klick kaufen | Truckoo
Klay Thompson Finals Stats
Ja Rule Net Worth (Money & Salary) 2024
12445 East Caley Avenue
Sams La Habra Gas Price
Look Who Got Busted Gregg County
Cheyenne Craigslist
Yesmovies.ta
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6153

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.