1
Starting Test 1, iterate...
10
Starting Test 2, walk events, records, and fields...
12
record 1 of type 1006(LOGIN) has 5 fields
14
event time: 1143146623.787:142
18
auid=4294967295 (unset)
22
record 1 of type 1300(SYSCALL) has 24 fields
24
event time: 1143146623.875:143
25
type=SYSCALL (SYSCALL)
26
arch=c000003e (x86_64)
27
syscall=188 (setxattr)
30
a0=7fffffa9a9f0 (7fffffa9a9f0)
31
a1=3958d11333 (3958d11333)
47
exe="/bin/login" (/bin/login)
48
subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
51
record 1 of type 1112(USER_LOGIN) has 10 fields
53
event time: 1143146623.879:146
54
type=USER_LOGIN (USER_LOGIN)
59
exe="/bin/login" (/bin/login)
67
Starting Test 3, walk events, records of 1 buffer...
69
record 1 of type 1112(USER_LOGIN) has 10 fields
71
event time: 1143146623.879:146
75
Starting Test 4, walk events, records of 1 file...
77
record 1 of type 1400(AVC) has 11 fields
78
line=1 file=./test.log
79
event time: 1170021493.977:293
81
seresult=denied (denied)
82
seperms=read,write (read,write)
84
comm="pickup" (pickup)
85
name="maildrop" (maildrop)
87
ino=14911367 (14911367)
88
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
89
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
92
record 2 of type 1300(SYSCALL) has 26 fields
93
line=2 file=./test.log
94
event time: 1170021493.977:293
95
type=SYSCALL (SYSCALL)
96
arch=c000003e (x86_64)
99
exit=-13 (-13(Permission denied))
100
a0=5555665d91b0 (5555665d91b0)
101
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
102
a2=5555665d91b8 (5555665d91b8)
107
auid=4294967295 (unset)
110
euid=89 (unknown(89))
111
suid=89 (unknown(89))
112
fsuid=89 (unknown(89))
113
egid=89 (unknown(89))
114
sgid=89 (unknown(89))
115
fsgid=89 (unknown(89))
117
comm="pickup" (pickup)
118
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
119
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
122
record 3 of type 1307(CWD) has 2 fields
123
line=3 file=./test.log
124
event time: 1170021493.977:293
126
cwd="/var/spool/postfix" (/var/spool/postfix)
128
record 4 of type 1302(PATH) has 10 fields
129
line=4 file=./test.log
130
event time: 1170021493.977:293
133
name="maildrop" (maildrop)
134
inode=14911367 (14911367)
136
mode=040730 (dir, 730)
137
ouid=89 (unknown(89))
138
ogid=90 (unknown(90))
140
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
142
event 2 has 1 records
143
record 1 of type 1101(USER_ACCT) has 11 fields
144
line=5 file=./test.log
145
event time: 1170021601.340:294
146
type=USER_ACCT (USER_ACCT)
149
auid=4294967295 (unset)
150
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
152
exe="/usr/sbin/crond" (/usr/sbin/crond)
156
res=success (success)
158
event 3 has 1 records
159
record 1 of type 1103(CRED_ACQ) has 11 fields
160
line=6 file=./test.log
161
event time: 1170021601.342:295
162
type=CRED_ACQ (CRED_ACQ)
165
auid=4294967295 (unset)
166
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
168
exe="/usr/sbin/crond" (/usr/sbin/crond)
172
res=success (success)
174
event 4 has 1 records
175
record 1 of type 1006(LOGIN) has 5 fields
176
line=7 file=./test.log
177
event time: 1170021601.343:296
181
auid=4294967295 (unset)
184
event 5 has 1 records
185
record 1 of type 1105(USER_START) has 11 fields
186
line=8 file=./test.log
187
event time: 1170021601.344:297
188
type=USER_START (USER_START)
192
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
194
exe="/usr/sbin/crond" (/usr/sbin/crond)
198
res=success (success)
200
event 6 has 1 records
201
record 1 of type 1104(CRED_DISP) has 11 fields
202
line=9 file=./test.log
203
event time: 1170021601.364:298
204
type=CRED_DISP (CRED_DISP)
208
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
210
exe="/usr/sbin/crond" (/usr/sbin/crond)
214
res=success (success)
216
event 7 has 1 records
217
record 1 of type 1106(USER_END) has 11 fields
218
line=10 file=./test.log
219
event time: 1170021601.366:299
220
type=USER_END (USER_END)
224
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
226
exe="/usr/sbin/crond" (/usr/sbin/crond)
230
res=success (success)
234
Starting Test 5, walk events, records of 2 files...
235
event 1 has 4 records
236
record 1 of type 1400(AVC) has 11 fields
238
event time: 1170021493.977:293
240
seresult=denied (denied)
241
seperms=read,write (read,write)
243
comm="pickup" (pickup)
244
name="maildrop" (maildrop)
246
ino=14911367 (14911367)
247
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
248
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
251
record 2 of type 1300(SYSCALL) has 26 fields
253
event time: 1170021493.977:293
254
type=SYSCALL (SYSCALL)
255
arch=c000003e (x86_64)
258
exit=-13 (-13(Permission denied))
259
a0=5555665d91b0 (5555665d91b0)
260
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
261
a2=5555665d91b8 (5555665d91b8)
266
auid=4294967295 (unset)
269
euid=89 (unknown(89))
270
suid=89 (unknown(89))
271
fsuid=89 (unknown(89))
272
egid=89 (unknown(89))
273
sgid=89 (unknown(89))
274
fsgid=89 (unknown(89))
276
comm="pickup" (pickup)
277
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
278
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
281
record 3 of type 1307(CWD) has 2 fields
283
event time: 1170021493.977:293
285
cwd="/var/spool/postfix" (/var/spool/postfix)
287
record 4 of type 1302(PATH) has 10 fields
289
event time: 1170021493.977:293
292
name="maildrop" (maildrop)
293
inode=14911367 (14911367)
295
mode=040730 (dir, 730)
296
ouid=89 (unknown(89))
297
ogid=90 (unknown(90))
299
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
301
event 2 has 1 records
302
record 1 of type 1101(USER_ACCT) has 11 fields
304
event time: 1170021601.340:294
305
type=USER_ACCT (USER_ACCT)
308
auid=4294967295 (unset)
309
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
311
exe="/usr/sbin/crond" (/usr/sbin/crond)
315
res=success (success)
317
event 3 has 1 records
318
record 1 of type 1103(CRED_ACQ) has 11 fields
320
event time: 1170021601.342:295
321
type=CRED_ACQ (CRED_ACQ)
324
auid=4294967295 (unset)
325
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
327
exe="/usr/sbin/crond" (/usr/sbin/crond)
331
res=success (success)
333
event 4 has 1 records
334
record 1 of type 1006(LOGIN) has 5 fields
336
event time: 1170021601.343:296
340
auid=4294967295 (unset)
343
event 5 has 1 records
344
record 1 of type 1105(USER_START) has 11 fields
346
event time: 1170021601.344:297
347
type=USER_START (USER_START)
351
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
353
exe="/usr/sbin/crond" (/usr/sbin/crond)
357
res=success (success)
359
event 6 has 1 records
360
record 1 of type 1104(CRED_DISP) has 11 fields
362
event time: 1170021601.364:298
363
type=CRED_DISP (CRED_DISP)
367
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
369
exe="/usr/sbin/crond" (/usr/sbin/crond)
373
res=success (success)
375
event 7 has 1 records
376
record 1 of type 1106(USER_END) has 11 fields
377
line=10 file=test.log
378
event time: 1170021601.366:299
379
type=USER_END (USER_END)
383
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
385
exe="/usr/sbin/crond" (/usr/sbin/crond)
389
res=success (success)
391
event 8 has 4 records
392
record 1 of type 1400(AVC) has 11 fields
393
line=1 file=test2.log
394
event time: 1170021493.977:293
396
seresult=denied (denied)
399
comm="pickup" (pickup)
400
name="maildrop" (maildrop)
402
ino=14911367 (14911367)
403
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
404
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
407
record 2 of type 1300(SYSCALL) has 26 fields
408
line=2 file=test2.log
409
event time: 1170021493.977:293
410
type=SYSCALL (SYSCALL)
411
arch=c000003e (x86_64)
414
exit=-13 (-13(Permission denied))
415
a0=5555665d91b0 (5555665d91b0)
416
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
417
a2=5555665d91b8 (5555665d91b8)
422
auid=4294967295 (unset)
425
euid=89 (unknown(89))
426
suid=89 (unknown(89))
427
fsuid=89 (unknown(89))
428
egid=89 (unknown(89))
429
sgid=89 (unknown(89))
430
fsgid=89 (unknown(89))
432
comm="pickup" (pickup)
433
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
434
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
437
record 3 of type 1307(CWD) has 2 fields
438
line=3 file=test2.log
439
event time: 1170021493.977:293
441
cwd="/var/spool/postfix" (/var/spool/postfix)
443
record 4 of type 1302(PATH) has 10 fields
444
line=4 file=test2.log
445
event time: 1170021493.977:293
448
name="maildrop" (maildrop)
449
inode=14911367 (14911367)
451
mode=040730 (dir, 730)
452
ouid=89 (unknown(89))
453
ogid=90 (unknown(90))
455
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
457
event 9 has 1 records
458
record 1 of type 1101(USER_ACCT) has 11 fields
459
line=5 file=test2.log
460
event time: 1170021601.340:294
461
type=USER_ACCT (USER_ACCT)
464
auid=4294967295 (unset)
465
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
467
exe="/usr/sbin/crond" (/usr/sbin/crond)
471
res=success (success)
473
event 10 has 1 records
474
record 1 of type 1103(CRED_ACQ) has 11 fields
475
line=6 file=test2.log
476
event time: 1170021601.342:295
477
type=CRED_ACQ (CRED_ACQ)
480
auid=4294967295 (unset)
481
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
483
exe="/usr/sbin/crond" (/usr/sbin/crond)
487
res=success (success)
489
event 11 has 1 records
490
record 1 of type 1006(LOGIN) has 5 fields
491
line=7 file=test2.log
492
event time: 1170021601.343:296
496
auid=4294967295 (unset)
499
event 12 has 1 records
500
record 1 of type 1105(USER_START) has 11 fields
501
line=8 file=test2.log
502
event time: 1170021601.344:297
503
type=USER_START (USER_START)
507
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
509
exe="/usr/sbin/crond" (/usr/sbin/crond)
513
res=success (success)
515
event 13 has 1 records
516
record 1 of type 1104(CRED_DISP) has 11 fields
517
line=9 file=test2.log
518
event time: 1170021601.364:298
519
type=CRED_DISP (CRED_DISP)
523
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
525
exe="/usr/sbin/crond" (/usr/sbin/crond)
529
res=success (success)
531
event 14 has 1 records
532
record 1 of type 1106(USER_END) has 11 fields
533
line=10 file=test2.log
534
event time: 1170021601.366:299
535
type=USER_END (USER_END)
539
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
541
exe="/usr/sbin/crond" (/usr/sbin/crond)
545
res=success (success)
549
Starting Test 6, search...
550
auid = 500 not found...which is correct
551
auid exists...which is correct
552
Testing BUFFER_ARRAY, stop on field
554
Testing BUFFER_ARRAY, stop on record
556
Testing BUFFER_ARRAY, stop on event
558
Testing test.log, stop on field
559
Found auid = 4294967295
560
Testing test.log, stop on record
562
Testing test.log, stop on event
566
Starting Test 7, compound search...
567
Found type = USER_START
571
Starting Test 8, buffer feed...
572
event 1 has 1 records
573
record 1 of type 1006(LOGIN) has 5 fields
575
event time: 1143146623.787:142
579
auid=4294967295 (unset)
582
event 2 has 1 records
583
record 1 of type 1300(SYSCALL) has 24 fields
585
event time: 1143146623.875:143
586
type=SYSCALL (SYSCALL)
587
arch=c000003e (x86_64)
588
syscall=188 (setxattr)
591
a0=7fffffa9a9f0 (7fffffa9a9f0)
592
a1=3958d11333 (3958d11333)
608
exe="/bin/login" (/bin/login)
609
subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
611
event 3 has 1 records
612
record 1 of type 1112(USER_LOGIN) has 10 fields
614
event time: 1143146623.879:146
615
type=USER_LOGIN (USER_LOGIN)
620
exe="/bin/login" (/bin/login)
624
res=success (success)
628
Starting Test 9, file feed...
629
event 1 has 4 records
630
record 1 of type 1400(AVC) has 11 fields
632
event time: 1170021493.977:293
634
seresult=denied (denied)
635
seperms=read,write (read,write)
637
comm="pickup" (pickup)
638
name="maildrop" (maildrop)
640
ino=14911367 (14911367)
641
scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
642
tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
645
record 2 of type 1300(SYSCALL) has 26 fields
647
event time: 1170021493.977:293
648
type=SYSCALL (SYSCALL)
649
arch=c000003e (x86_64)
652
exit=-13 (-13(Permission denied))
653
a0=5555665d91b0 (5555665d91b0)
654
a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
655
a2=5555665d91b8 (5555665d91b8)
660
auid=4294967295 (unset)
663
euid=89 (unknown(89))
664
suid=89 (unknown(89))
665
fsuid=89 (unknown(89))
666
egid=89 (unknown(89))
667
sgid=89 (unknown(89))
668
fsgid=89 (unknown(89))
670
comm="pickup" (pickup)
671
exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
672
subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
675
record 3 of type 1307(CWD) has 2 fields
677
event time: 1170021493.977:293
679
cwd="/var/spool/postfix" (/var/spool/postfix)
681
record 4 of type 1302(PATH) has 10 fields
683
event time: 1170021493.977:293
686
name="maildrop" (maildrop)
687
inode=14911367 (14911367)
689
mode=040730 (dir, 730)
690
ouid=89 (unknown(89))
691
ogid=90 (unknown(90))
693
obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
695
event 2 has 1 records
696
record 1 of type 1101(USER_ACCT) has 11 fields
698
event time: 1170021601.340:294
699
type=USER_ACCT (USER_ACCT)
702
auid=4294967295 (unset)
703
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
705
exe="/usr/sbin/crond" (/usr/sbin/crond)
709
res=success (success)
711
event 3 has 1 records
712
record 1 of type 1103(CRED_ACQ) has 11 fields
714
event time: 1170021601.342:295
715
type=CRED_ACQ (CRED_ACQ)
718
auid=4294967295 (unset)
719
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
721
exe="/usr/sbin/crond" (/usr/sbin/crond)
725
res=success (success)
727
event 4 has 1 records
728
record 1 of type 1006(LOGIN) has 5 fields
730
event time: 1170021601.343:296
734
auid=4294967295 (unset)
737
event 5 has 1 records
738
record 1 of type 1105(USER_START) has 11 fields
740
event time: 1170021601.344:297
741
type=USER_START (USER_START)
745
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
747
exe="/usr/sbin/crond" (/usr/sbin/crond)
751
res=success (success)
753
event 6 has 1 records
754
record 1 of type 1104(CRED_DISP) has 11 fields
756
event time: 1170021601.364:298
757
type=CRED_DISP (CRED_DISP)
761
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
763
exe="/usr/sbin/crond" (/usr/sbin/crond)
767
res=success (success)
769
event 7 has 1 records
770
record 1 of type 1106(USER_END) has 11 fields
772
event time: 1170021601.366:299
773
type=USER_END (USER_END)
777
subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
779
exe="/usr/sbin/crond" (/usr/sbin/crond)
783
res=success (success)
787
Finished non-admin tests