Enabling or Disabling Auditing on Linux and UNIX Computers | Delinea (2024)

After you install the agent, you can enable auditing with the dacontrol command. The dacontrol command links all shells to the cdash shell wrapper by way of NSS. When a user opens a terminal, cdash is automatically loaded instead of the user’s shell, then cdash loads the appropriate shell for the user and begins auditing the session.

You can also choose to enable video capture editing for an installation but disable it for specific computers. You disable or enable video capture auditing for a specific computer or set of computers by using group policy settings or by modifying the agent.video.capture setting. For details, see the Group Policy Guide or the Configuration and Tuning Reference Guide.

Shell or Terminal Window Auditing

To enable auditing on a Linux or UNIX computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -e option:

    dacontrol -e

  3. Run dacontrol again to verify that auditing has been enabled or run dainfo.

    For example, the output of the dacontrol command shows something like this:

    dacontrol --query

    This machine has been configured through group policy to use installation 'DefaultInstallation'

    DirectAudit NSS module: Active

    DirectAudit is not configured to audit individual commands.

    When you enable auditing, the NSS module shows as active. You can also see if auditing is enabled or not for a system in the Audit Manager console.

After you enable auditing on a Linux or UNIX computer, you can control whether the auditing of shell activity applies for all users or for selected users by using role assignments. If auditing is enabled and the agent is not running, users with an active role assignment that requires logging are not allowed to log in.

For more information about configuring and assigning roles, see the Administrator’s Guide for Linux and UNIX.

To disable auditing on a Linux or UNIX computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -d option or the --disable option:

    dacontrol -d

    dacontrol --disable

  3. Run dacontrol again to verify that auditing has been disabled or run dainfo.

    For example:

    dacontrol --query

    This machine has been configured through group policy to use installation 'DefaultInstallation'

    DirectAudit NSS module: Inactive

    DirectAudit is not configured to audit individual commands

    When you disable auditing, the NSS module shows as inactive. You can also see if auditing is enabled or not for a system in the Audit Manager console.

Linux Desktop Auditing

In addition to shell auditing, for some Linux systems you can also enable desktop auditing. When desktop auditing is enabled, the user's entire screen is continuously monitored to record all graphical interactions. More specifically, desktop auditing captures the following:

  • The application name and window title when the user switches the focus to that application. For example, if a user opens a web browser or a terminal window.
  • Changes to the application window title that currently has focus. For example, if a user opens a web browser and goes to a new web page, desktop auditing records the title of a web page.

The supported platforms for Linux desktop auditing are as follows:

  • RHEL 6, 7, and 8 with GNOME v3
  • CentOS 6, 7, and 8 with GNOME v3

Linux sessions must be running X as the primary display manager (not Wayland).

Linux desktop auditing requires shell session auditing.

To enable desktop auditing on a Linux computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -x option or the --desktop-audit option:

    dacontrol -x

    dacontrol --desktop-audit

    To enable both shell and desktop auditing at the same time, use both the -e and -x options:

    dacontrol -e -x

  3. Run dainfo to verify that desktop auditing has been enabled.

    For example, the relevant information from the dainfo command looks like this:

    Pinging adclient: adclient is available
    Daemon status: Online
    Current installation: 'DirectAudit' (configured locally)
    Current collector: test.acme.com:5063:HOST/[email protected]
    DirectAudit NSS module: Active
    ...DirectAudit desktop auditing: Enabled
    User (root) audited status: Yes

    When you enable auditing, the desktop auditing module shows as Enabled. You can also see if auditing is enabled or not for a system in the Audit Manager console.

To disable desktop auditing on a Linux computer:

  1. Log on as a user with root privileges.

  2. Run dacontrol with the -z option or the --no-desktop-audit option:

    dacontrol -z

    dacontrol --no-desktop-audit

  3. Run dainfo to verify that desktop auditing has been disabled.

    For example, the relevant information from the dainfo command looks like this:

    Pinging adclient: adclient is available
    Daemon status: Online

    Current installation: 'DirectAudit' (configured locally)
    Current collector: test.acme.com:5063:HOST/[email protected]
    DirectAudit NSS module: Inactive
    ...DirectAudit desktop auditing: Disabled
    User (root) audited status: No

    When you disable auditing, the desktop auditing module shows as Disabled. You can also see if auditing is enabled or not for a system in the Audit Manager console.

Enabling or Disabling Auditing on Linux and UNIX Computers | Delinea (2024)
Top Articles
Cashflow einfach erklärt: Bedeutung & Berechnung
Breast Reduction Recovery
Kansas City Kansas Public Schools Educational Audiology Externship in Kansas City, KS for KCK public Schools
Ofw Pinoy Channel Su
Soap2Day Autoplay
Wild Smile Stapleton
Unlocking the Enigmatic Tonicamille: A Journey from Small Town to Social Media Stardom
Cinepacks.store
William Spencer Funeral Home Portland Indiana
Nichole Monskey
Ukraine-Russia war: Latest updates
Ladyva Is She Married
How to watch free movies online
Slushy Beer Strain
The fabulous trio of the Miller sisters
Finger Lakes Ny Craigslist
Rachel Griffin Bikini
Inside the life of 17-year-old Charli D'Amelio, the most popular TikTok star in the world who now has her own TV show and clothing line
Red Devil 9664D Snowblower Manual
Craigslist Missoula Atv
Kamzz Llc
BMW K1600GT (2017-on) Review | Speed, Specs & Prices
Team C Lakewood
Cincinnati Adult Search
Babbychula
Aol News Weather Entertainment Local Lifestyle
Idle Skilling Ascension
Dtm Urban Dictionary
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
Log in or sign up to view
Metro By T Mobile Sign In
Montrose Colorado Sheriff's Department
School Tool / School Tool Parent Portal
Midsouthshooters Supply
Crazy Balls 3D Racing . Online Games . BrightestGames.com
Has any non-Muslim here who read the Quran and unironically ENJOYED it?
Jason Brewer Leaving Fox 25
Trap Candy Strain Leafly
Let's co-sleep on it: How I became the mom I swore I'd never be
Lake Kingdom Moon 31
Mcalister's Deli Warrington Reviews
Pain Out Maxx Kratom
Leland Nc Craigslist
Flappy Bird Cool Math Games
Cch Staffnet
Phone Store On 91St Brown Deer
News & Events | Pi Recordings
Server Jobs Near
The top 10 takeaways from the Harris-Trump presidential debate
Cvs Minute Clinic Women's Services
Where To Find Mega Ring In Pokemon Radical Red
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6153

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.