The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect kernel audit status | sudo auditctl -s -i | View examples |
| Inspect the audit daemon | sudo systemctl status auditd --no-pager | View examples |
| List active kernel rules | sudo auditctl -l | View examples |
| Check whether rules changed | sudo augenrules --check | View examples |
| Build the merged rules file | sudo augenrules | View examples |
| Build and load persistent rules | sudo augenrules --load | View examples |
| Audit writes and metadata changes | -a always,exit -F arch=b64 -F path=/etc/sudoers -F \
perm=wa -k sudoers_change | View examples |
| Audit a directory tree | -a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F \
perm=wa -k sudoers_change | View examples |
| Audit failed file access | -a always,exit -F arch=b64 -S openat,truncate -F \
dir=/etc/ -F success=0 -k etc_access_denied | View examples |
| Search by rule key | sudo ausearch --start today --key sudoers_change -i | View examples |
| Search failed events | sudo ausearch --start recent --success no -i | View examples |
| Summarize authentication activity | sudo aureport --auth --summary -i | View examples |
| Request auditd internal state | sudo auditctl --signal state | View examples |
| Lock the audit configuration | -e 2 | View examples |
The Linux Audit framework records security-relevant activity in the kernel and delivers it to auditd for durable storage and analysis. It is an evidence and accountability system, not an access-control mechanism: an audit rule can record an attempted change but cannot prevent it. Treat rule loading, daemon configuration, failure policy, and immutable mode as production security changes. Capture current state, test on a compatible staging host, preserve console recovery, and verify that events arrive without loss before relying on the trail.
Step by step
Detailed examples
Establish live health and understand the trust boundary
The kernel evaluates audit rules and queues records; auditd consumes the queue and writes the trail. Check both layers and compare active rules with persistent policy. A nonzero lost count means evidence was discarded, while a growing backlog indicates delivery pressure. Audit records support detection, investigation, and accountability, but they do not deny an operation; use permissions, capabilities, MAC policy, sandboxing, or another preventive control for enforcement.
sudo auditctl -s -i
sudo auditctl -l
sudo systemctl status auditd --no-pager Stage persistent fragments before changing the kernel
augenrules naturally sorts files ending in .rules under /etc/audit/rules.d and constructs /etc/audit/audit.rules. Its --check option only tells whether the merged output needs updating; it is not a syntax-only validator. There is no equivalent of a harmless compiler dry-run for every kernel-dependent rule. Review ordering, build and load on a disposable host with the same architecture and kernel capabilities, then schedule the production load with console recovery. A load changes security telemetry immediately and can fail when immutable mode is active.
sudo augenrules --check
sudo auditctl -l
# After peer review and successful testing on a compatible staging host:
# sudo augenrules --load Prefer syscall-form path and directory rules
The older -w watch syntax remains compatible but is deprecated because of performance. Syscall-form rules combine an exit filter, architecture, path or directory, permission mask, and searchable key. A directory rule is recursive but cannot target the filesystem root, and wildcards are unsupported. On bi-architecture systems, mirror an applicable rule for b32 only when the host actually supports that ABI; architecture must precede syscall or permission selection.
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -k sudoers_change
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -k sudoers_change
# Add equivalent b32 rules only on a host that supports the 32-bit syscall ABI. Constrain syscall rules for fidelity and performance
Exit-list syscall rules are evaluated on system calls and can impose material overhead when broad. Combine syscalls sharing identical filters, specify the ABI before syscall lookup, and narrow by directory, executable, identity, or result. The audit UID (auid or loginuid) identifies the original login identity and differs from effective uid after sudo. Test representative success and failure paths, because an apparently valid filter can produce no useful events or an unmanageable volume.
-a always,exit -F arch=b64 -S openat,truncate -F dir=/etc/ -F success=0 -k etc_access_denied
# If the compatible 32-bit ABI is enabled, assess and test a corresponding arch=b32 rule. Search complete events instead of grepping record lines
One audit event may contain several records sharing the same timestamp and serial number. ausearch understands that grouping and can filter by key, time, identity, file, syscall, or success; aureport summarizes the same trail. Interpreted output is convenient, but unenriched logs resolve numeric identities against the current host and can mislead after accounts change. Preserve raw records for evidence and correlate the complete event before drawing conclusions.
sudo ausearch --start today --key sudoers_change -i
sudo ausearch --start recent --success no -i
sudo aureport --auth --summary -i Engineer queue, disk, and failure behavior deliberately
Backlog size, rate limiting, disk thresholds, rotation, and failure actions determine whether audit evidence survives a spike or storage incident. Security-sensitive failure modes can degrade availability or deliberately halt a host, so do not copy a compliance profile blindly. Size policy from measured peak event rates, protect log permissions, forward evidence where required, monitor lost and backlog values, and exercise disk-pressure procedures in a non-production environment.
sudo auditctl -s -i
sudo auditctl --signal state
sudo stat /run/audit/auditd.state
sudo journalctl -u auditd --since today --no-pager Make immutable mode the final, rehearsed step
A final -e 2 directive makes the running audit configuration immutable: later changes are denied and recorded, and only a reboot clears the lock. augenrules deliberately emits the last -e directive last. Enable it only after the complete rule set, capacity behavior, boot path, maintenance workflow, and recovery access are verified. After any authorized deployment, confirm active rules and generate a harmless, uniquely keyed test event in a controlled environment to prove end-to-end collection.
# Place in the naturally last rules fragment only after full validation.
-e 2
# Reboot is required before the kernel audit configuration can be changed again. Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



