Unable to use aa-logprof to generate log in audit.log
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
AppArmor |
New
|
Undecided
|
Unassigned |
Bug Description
Hi,
In my setup , we have configure audit.log to have the apparamor messages. I enabled complain mode for my process and i get the error in audit.log in the following format.
node=compute-
But when i try to run aa-logprof on this . It is not able to parse this message . Is there some configuration i am missing. How can I generate the logs from this audit.log.
Please help!!
These are the package i have installed.
root@compute-0-1:~# dpkg -l | grep apparmor
ii apparmor 2.10.95-
ii apparmor-utils 2.10.95-
ii libapparmor-perl 2.10.95-
ii libapparmor1:amd64 2.10.95-
ii python3-apparmor 2.10.95-
ii python3-libapparmor 2.10.95-
Looks like libapparmor doesn't like this log format :-(
If I remove the node=... part (so that the line starts with type=AVC), it can be parsed.
As a workaround, try
aa-logprof -f <( sed 's/node= compute- 0-1.domain. tld //' audit.log)