Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Security event auditing with auditd

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 497 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dionysis.skordoulis
      last edited by

      I see that auditd is disabled in /etc/defaults/rc.conf

      auditd_enable="NO"	# Run the audit daemon.
      auditd_program="/usr/sbin/auditd"	# Path to the audit daemon.
      auditd_flags=""		# Which options to pass to the audit daemon.
      

      I would like to enable it with some certain events that are not covered with the pfSense logging feature, such as auditing of command line arguments within a shell. In addition, these to be forward via rsyslog.

      Is this possible? Any insights are more than welcome.

      1 Reply Last reply Reply Quote 1
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        pfSense doesn't use the FreeBSD RC system so making changes there does nothing.

        Also auditd is not included by default so to use that would require a number of custom changes.

        I don't see any references to other attempts so some development would be required.

        Steve

        D 1 Reply Last reply Reply Quote 1
        • D
          dad98253 @stephenw10
          last edited by dad98253

          @stephenw10
          I would welcome such a feature, too. The netgate/pfsense firewall is possibly the most security critical system on the network that it protects. To not have auditd enabled by default makes no sense to me.

          -John

          p.s., (off subject) BTW, it would be really nice if we had a tripwire plugin as well!

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Both those things should be a feature request in redmine if there is not something existing: https://redmine.pfsense.org/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.