Event: execve
Time: Wed Nov 21 17:22:43 07 JST
PID: 8025
PPID: 8006
User/Grp: 109/20(test/users)
Groups: 20(users)
Effective privileges: "BASIC"
Permitted privileges: "BASIC"
Retained privileges: "BASIC"
Compartment id: 2
Audit tag: 0: -1:test:200711210821
TTY: unknown
Return1: 0
Arg 1 (file info):
given path = "/usr/sbin/getrules"
inode = 12671
device = 64, 0x3
mode = 0100555
owner uid/gid = 2/2
type = regular file
Arg 2 (argument list):
arg #1 = "/usr/sbin/getrules"
arg #2 = "init"
Other (file info):
inode = -1
|