The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect kernel audit statussudo auditctl -s -iView examples
Inspect the audit daemonsudo systemctl status auditd --no-pagerView examples
List active kernel rulessudo auditctl -lView examples
Check whether rules changedsudo augenrules --checkView examples
Build the merged rules filesudo augenrulesView examples
Build and load persistent rulessudo augenrules --loadView examples
Audit writes and metadata changes-a always,exit -F arch=b64 -F path=/etc/sudoers -F \ perm=wa -k sudoers_changeView examples
Audit a directory tree-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F \ perm=wa -k sudoers_changeView examples
Audit failed file access-a always,exit -F arch=b64 -S openat,truncate -F \ dir=/etc/ -F success=0 -k etc_access_deniedView examples
Search by rule keysudo ausearch --start today --key sudoers_change -iView examples
Search failed eventssudo ausearch --start recent --success no -iView examples
Summarize authentication activitysudo aureport --auth --summary -iView examples
Request auditd internal statesudo auditctl --signal stateView examples
Lock the audit configuration-e 2View examples

The Linux Audit framework records security-relevant activity in the kernel and delivers it to auditd for durable storage and analysis. It is an evidence and accountability system, not an access-control mechanism: an audit rule can record an attempted change but cannot prevent it. Treat rule loading, daemon configuration, failure policy, and immutable mode as production security changes. Capture current state, test on a compatible staging host, preserve console recovery, and verify that events arrive without loss before relying on the trail.

Step by step

Detailed examples

01

Establish live health and understand the trust boundary

The kernel evaluates audit rules and queues records; auditd consumes the queue and writes the trail. Check both layers and compare active rules with persistent policy. A nonzero lost count means evidence was discarded, while a growing backlog indicates delivery pressure. Audit records support detection, investigation, and accountability, but they do not deny an operation; use permissions, capabilities, MAC policy, sandboxing, or another preventive control for enforcement.

Read-only production health inspection
sudo auditctl -s -i
sudo auditctl -l
sudo systemctl status auditd --no-pager
Back to quick reference ↑
02

Stage persistent fragments before changing the kernel

augenrules naturally sorts files ending in .rules under /etc/audit/rules.d and constructs /etc/audit/audit.rules. Its --check option only tells whether the merged output needs updating; it is not a syntax-only validator. There is no equivalent of a harmless compiler dry-run for every kernel-dependent rule. Review ordering, build and load on a disposable host with the same architecture and kernel capabilities, then schedule the production load with console recovery. A load changes security telemetry immediately and can fail when immutable mode is active.

Review-first deployment sequence
sudo augenrules --check
sudo auditctl -l
# After peer review and successful testing on a compatible staging host:
# sudo augenrules --load
Back to quick reference ↑
03

Prefer syscall-form path and directory rules

The older -w watch syntax remains compatible but is deprecated because of performance. Syscall-form rules combine an exit filter, architecture, path or directory, permission mask, and searchable key. A directory rule is recursive but cannot target the filesystem root, and wildcards are unsupported. On bi-architecture systems, mirror an applicable rule for b32 only when the host actually supports that ABI; architecture must precede syscall or permission selection.

Persistent sudoers change policy fragment
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -k sudoers_change
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -k sudoers_change
# Add equivalent b32 rules only on a host that supports the 32-bit syscall ABI.
Back to quick reference ↑
04

Constrain syscall rules for fidelity and performance

Exit-list syscall rules are evaluated on system calls and can impose material overhead when broad. Combine syscalls sharing identical filters, specify the ABI before syscall lookup, and narrow by directory, executable, identity, or result. The audit UID (auid or loginuid) identifies the original login identity and differs from effective uid after sudo. Test representative success and failure paths, because an apparently valid filter can produce no useful events or an unmanageable volume.

Focused failed-access rules
-a always,exit -F arch=b64 -S openat,truncate -F dir=/etc/ -F success=0 -k etc_access_denied
# If the compatible 32-bit ABI is enabled, assess and test a corresponding arch=b32 rule.
Back to quick reference ↑
05

Search complete events instead of grepping record lines

One audit event may contain several records sharing the same timestamp and serial number. ausearch understands that grouping and can filter by key, time, identity, file, syscall, or success; aureport summarizes the same trail. Interpreted output is convenient, but unenriched logs resolve numeric identities against the current host and can mislead after accounts change. Preserve raw records for evidence and correlate the complete event before drawing conclusions.

Investigate and summarize recent evidence
sudo ausearch --start today --key sudoers_change -i
sudo ausearch --start recent --success no -i
sudo aureport --auth --summary -i
Back to quick reference ↑
06

Engineer queue, disk, and failure behavior deliberately

Backlog size, rate limiting, disk thresholds, rotation, and failure actions determine whether audit evidence survives a spike or storage incident. Security-sensitive failure modes can degrade availability or deliberately halt a host, so do not copy a compliance profile blindly. Size policy from measured peak event rates, protect log permissions, forward evidence where required, monitor lost and backlog values, and exercise disk-pressure procedures in a non-production environment.

Collect capacity evidence without changing policy
sudo auditctl -s -i
sudo auditctl --signal state
sudo stat /run/audit/auditd.state
sudo journalctl -u auditd --since today --no-pager
Back to quick reference ↑
07

Make immutable mode the final, rehearsed step

A final -e 2 directive makes the running audit configuration immutable: later changes are denied and recorded, and only a reboot clears the lock. augenrules deliberately emits the last -e directive last. Enable it only after the complete rule set, capacity behavior, boot path, maintenance workflow, and recovery access are verified. After any authorized deployment, confirm active rules and generate a harmless, uniquely keyed test event in a controlled environment to prove end-to-end collection.

Finalization fragment and verification checklist
# Place in the naturally last rules fragment only after full validation.
-e 2
# Reboot is required before the kernel audit configuration can be changed again.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux Audit Projectauditctl(8)man7.org
  2. Linux Audit Projectauditd(8)man7.org
  3. Linux Audit Projectaugenrules(8)man7.org
  4. Linux Audit Projectausearch(8)man7.org
  5. Linux Audit ProjectLinux Audit userspace repositorygithub.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback