gpt4 book ai didi

linux - 在 docker 容器中运行 auditd

转载 作者:太空狗 更新时间:2023-10-29 12:41:07 27 4
gpt4 key购买 nike

我正在尝试在 centos docker 容器中配置 rsyslog 客户端,我注意到以下错误。看起来 rsyslogd 由于 auditd 失败而退出。

知道如何让 rsyslog 服务在 centos docker 容器内工作吗?

试过这个 suggestion但没有运气。

May 16 09:49:35 ad5de951dcd4 auditd[312]: Started dispatcher: /sbin/audispd pid: 316
May 16 09:49:35 ad5de951dcd4 auditd[312]: Unable to set initial audit startup state to 'enable', exiting
May 16 09:49:35 ad5de951dcd4 auditd[312]: The audit daemon is exiting.
May 16 09:49:35 ad5de951dcd4 systemd: auditd.service: main process exited, code=exited, status=1/FAILURE
May 16 09:49:35 ad5de951dcd4 audispd: syslog plugin initialized
May 16 09:49:35 ad5de951dcd4 audispd: audispd initialized with q_depth=150 and 1 active plugins
May 16 09:49:35 ad5de951dcd4 augenrules: /sbin/augenrules: No change
May 16 09:49:35 ad5de951dcd4 auditctl: The audit system is disabled
May 16 09:49:35 ad5de951dcd4 systemd: Failed to start Security Auditing Service.
May 16 09:49:35 ad5de951dcd4 systemd: Unit auditd.service entered failed state.
May 16 09:49:35 ad5de951dcd4 systemd: auditd.service failed.
May 16 09:49:53 ad5de951dcd4 systemd: Starting Security Auditing Service...
May 16 09:49:53 ad5de951dcd4 auditd[330]: Started dispatcher: /sbin/audispd pid: 333
May 16 09:49:53 ad5de951dcd4 auditd[330]: Unable to set initial audit startup state to 'enable', exiting
May 16 09:49:53 ad5de951dcd4 auditd[330]: The audit daemon is exiting.
May 16 09:49:53 ad5de951dcd4 systemd: auditd.service: main process exited, code=exited, status=1/FAILURE
May 16 09:49:53 ad5de951dcd4 audispd: syslog plugin initialized
May 16 09:49:53 ad5de951dcd4 audispd: audispd initialized with q_depth=150 and 1 active plugins
May 16 09:49:53 ad5de951dcd4 augenrules: /sbin/augenrules: No change
May 16 09:49:53 ad5de951dcd4 auditctl: The audit system is disabled
May 16 09:49:53 ad5de951dcd4 systemd: Failed to start Security Auditing Service.
May 16 09:49:53 ad5de951dcd4 systemd: Unit auditd.service entered failed state.
May 16 09:49:53 ad5de951dcd4 systemd: auditd.service failed.
May 16 10:09:57 ad5de951dcd4 systemd: Reloading.
May 16 10:10:02 ad5de951dcd4 systemd: Reloading.
May 16 10:10:10 ad5de951dcd4 rsyslogd: [origin software="rsyslogd" swVersion="7.4.7" x-pid="421" x-info="http://www.rsyslog.com"] exiting on signal 2.

最佳答案

抱歉,这不能直接解决 rsyslog 问题,但会为您提供调查途径。

auditd 目前在 docker 中不起作用(我遇到了类似的问题),请参阅此线程:
https://www.redhat.com/archives/linux-audit/2016-February/msg00011.html

因此,如果 auditd 对您的使用不是至关重要的,您应该找到一种在 rsyslog 中禁用它的方法。

关于linux - 在 docker 容器中运行 auditd,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/44015797/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com