diff --git a/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/ansible/shared.yml b/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/ansible/shared.yml index c47c0f21f3c..af9a41c4861 100644 --- a/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/ansible/shared.yml +++ b/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/ansible/shared.yml @@ -17,12 +17,11 @@ state: absent loop: "{{ find_rules_d.files | map(attribute='path') | list + ['/etc/audit/audit.rules'] }}" -- name: Add Audit -e option into /etc/audit/rules.d/immutable.rules and /etc/audit/audit.rules +- name: Add Audit -e option into /etc/audit/rules.d/90-immutable.rules lineinfile: path: "{{ item }}" create: True line: "-e 2" mode: g-rwx,o-rwx loop: - - "/etc/audit/audit.rules" - - "/etc/audit/rules.d/immutable.rules" + - "/etc/audit/rules.d/90-immutable.rules" diff --git a/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/bash/shared.sh b/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/bash/shared.sh index 436dfd26c15..1c13d2b7ecf 100644 --- a/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/bash/shared.sh +++ b/linux_os/guide/auditing/auditd_configure_rules/audit_rules_immutable/bash/shared.sh @@ -14,7 +14,7 @@ find /etc/audit /etc/audit/rules.d -maxdepth 1 -type f -name '*.rules' -exec sed # * /etc/audit/audit.rules file (for auditctl case) # * /etc/audit/rules.d/immutable.rules (for augenrules case) -for AUDIT_FILE in "/etc/audit/audit.rules" "/etc/audit/rules.d/immutable.rules" +for AUDIT_FILE in "/etc/audit/audit.rules" "/etc/audit/rules.d/90-immutable.rules" do echo '' >> $AUDIT_FILE echo '# Set the audit.rules configuration immutable per security requirements' >> $AUDIT_FILE