I spent a little time thinking about what makes sense to log in the operating system level.
There’s seemingly a lot of attack surface to consider, and I took some time thinking about first principles
To write logs that can me moved off a host using a daemon to a remote logging server.
With two things in mind.
The logs result in information useful for forensic or incident response teams, where the incident was detected by other means.
Logs that are stored that allow:
- querying, alerting and other mechanisms that allow the organization to respond to security incidents.
a quick run of ‘sudo aureport’
yields useful at a glance information.
Summary Report
Range of time in logs: 06/30/2026 01:20:07.460 - 06/30/2026 08:22:07.068
Selected time for report: 06/30/2026 01:20:07 - 06/30/2026 08:22:07.068
Number of changes in configuration: 0
Number of changes to accounts, groups, or roles: 0
Number of logins: 0
Number of failed logins: 0
Number of authentications: 0
Number of failed authentications: 0
Number of users: 5
Number of terminals: 7
Number of host names: 6
Number of executables: 84
Number of commands: 120
Number of files: 236
Number of AVC’s: 0
Number of MAC events: 0
Number of failed syscalls: 3637
Number of anomaly events: 0
Number of responses to anomaly events: 0
Number of crypto events: 0
Number of integrity events: 0
Number of virt events: 0
Number of keys: 12
Number of process IDs: 16361
Number of events: 32678
What are some considerations that you implement?
Or would implement?