Linux auditd generated audit.log files
I'm currently using AdventNet's EventLog Analyzer for auditing of a secure Windows machine and thought it would be nice to use for a secure RHEL 5.2 cluster as well since people would only need to use one interface. It seems to do well with the syslog entries, but I don't see anything about getting the auditd/ audit.log entries into it. Can anyone point me to some information on how to do this or should I give up and go with Prewikka?
Attached is a log sample.
Dan
New to ADSelfService Plus?