clamd starts with: 1. aa-complain clamd 2. invoke-rc.d clamav-daemon restart
No clamd entries in syslog. audit.log after starting clamd: type=USER_AUTH msg=audit(1428468600.638:193): pid=8314 uid=1000 auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="hartwig" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/18 res=success' type=USER_ACCT msg=audit(1428468600.638:194): pid=8314 uid=1000 auid=4294967295 ses=4294967295 msg='op=PAM:accounting acct="hartwig" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/18 res=success' type=USER_START msg=audit(1428468600.658:195): pid=8314 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/18 res=success' type=AVC msg=audit(1428468604.378:196): apparmor="STATUS" operation="profile_replace" profile="unconfined" name="/usr/sbin/clamd" pid=8319 comm="apparmor_parser" type=SYSCALL msg=audit(1428468604.378:196): arch=40000003 syscall=4 success=yes exit=26185 a0=3 a1=9c6677c a2=6649 a3=bfbf36c4 items=0 ppid=8315 pid=8319 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts18 ses=4294967295 comm="apparmor_parser" exe="/sbin/apparmor_parser" key=(null) type=USER_END msg=audit(1428468604.450:197): pid=8314 uid=0 auid=4294967295 ses=4294967295 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=/dev/pts/18 res=success'
But - Eicar file can be copied, no error msg, no log entry
clamd starts with:
1. aa-complain clamd
2. invoke-rc.d clamav-daemon restart
No clamd entries in syslog. 1428468600. 638:193) : pid=8314 uid=1000 auid=4294967295 ses=4294967295 msg='op= PAM:authenticat ion acct="hartwig" exe="/usr/bin/sudo" hostname=? addr=? terminal= /dev/pts/ 18 res=success' 1428468600. 638:194) : pid=8314 uid=1000 auid=4294967295 ses=4294967295 msg='op= PAM:accounting acct="hartwig" exe="/usr/bin/sudo" hostname=? addr=? terminal= /dev/pts/ 18 res=success' 1428468600. 658:195) : pid=8314 uid=0 auid=4294967295 ses=4294967295 msg='op= PAM:session_ open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal= /dev/pts/ 18 res=success' 1428468604. 378:196) : apparmor="STATUS" operation= "profile_ replace" profile= "unconfined" name="/ usr/sbin/ clamd" pid=8319 comm="apparmor_ parser" 1428468604. 378:196) : arch=40000003 syscall=4 success=yes exit=26185 a0=3 a1=9c6677c a2=6649 a3=bfbf36c4 items=0 ppid=8315 pid=8319 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts18 ses=4294967295 comm="apparmor_ parser" exe="/sbin/ apparmor_ parser" key=(null) 1428468604. 450:197) : pid=8314 uid=0 auid=4294967295 ses=4294967295 msg='op= PAM:session_ close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal= /dev/pts/ 18 res=success'
audit.log after starting clamd:
type=USER_AUTH msg=audit(
type=USER_ACCT msg=audit(
type=USER_START msg=audit(
type=AVC msg=audit(
type=SYSCALL msg=audit(
type=USER_END msg=audit(
But - Eicar file can be copied, no error msg, no log entry