improved audit handler and related rules
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
6e78559776
commit
e69c18fa1c
|
@ -237,9 +237,7 @@
|
||||||
changed_when: true
|
changed_when: true
|
||||||
|
|
||||||
- name: Auditd rules reload
|
- name: Auditd rules reload
|
||||||
when:
|
when: ('"No change" not in discovered_augenrules_check.stdout') or prelim_auditd_immutable_check.rc == 1
|
||||||
- not prelim_auditd_immutable_check or
|
|
||||||
'"No change" not in ubtu24cis_rule_6_2_3_21_grep -iR augen_check.stdout'
|
|
||||||
ansible.builtin.command: augenrules --load
|
ansible.builtin.command: augenrules --load
|
||||||
changed_when: true
|
changed_when: true
|
||||||
|
|
||||||
|
|
|
@ -218,7 +218,7 @@
|
||||||
- name: "PRELIM | AUDIT | Check if auditd is immutable before changes"
|
- name: "PRELIM | AUDIT | Check if auditd is immutable before changes"
|
||||||
when: "'auditd' in ansible_facts.packages"
|
when: "'auditd' in ansible_facts.packages"
|
||||||
tags: always
|
tags: always
|
||||||
ansible.builtin.shell: auditctl -l | grep -c '-e 2'
|
ansible.builtin.shell: auditctl -s | grep "enabled 2"
|
||||||
changed_when: false
|
changed_when: false
|
||||||
failed_when: prelim_auditd_immutable_check.rc not in [ 0, 1 ]
|
failed_when: prelim_auditd_immutable_check.rc not in [ 0, 1 ]
|
||||||
register: prelim_auditd_immutable_check
|
register: prelim_auditd_immutable_check
|
||||||
|
|
|
@ -277,3 +277,4 @@
|
||||||
- auditd
|
- auditd
|
||||||
ansible.builtin.command: augenrules --check
|
ansible.builtin.command: augenrules --check
|
||||||
changed_when: false
|
changed_when: false
|
||||||
|
register: discovered_augenrules_check
|
||||||
|
|
Loading…
Reference in New Issue