mirror of
https://gitlab.com/apparmor/apparmor.git
synced 2025-03-10 03:34:23 +01:00

syslog, along with testcases. This should work for both old and new style log messages, as well as with dmesg timestamps enabled in the kernel ("echo 1 > /sys/module/printk/parameters/printk_time"). This patch applies on top of the previous patch sent to support the type=15xx messages.
12 lines
244 B
Text
12 lines
244 B
Text
START
|
|
File: test_multi/testcase15.in
|
|
Event type: AA_RECORD_DENIED
|
|
Audit ID: 1189201672.746:537
|
|
Operation: file_lock
|
|
Mask: k
|
|
Denied Mask: k
|
|
Profile: /usr/sbin/nmbd
|
|
Name: /var/run/samba/unexpected.tdb
|
|
PID: 4316
|
|
Epoch: 1189201672
|
|
Audit subid: 537
|