Skip to content

Commit 940ed98

Browse files
z-bsodChristoph Sieber
andauthored
disable systemd audit logging (#902)
* os_hardening: disable systemd audit logging disable audit logging via systemd-journald when enabling auditd as this leads to duplicate logs in the journal or even /var/log/messages depending on the configuration Signed-off-by: Christoph Sieber <Christoph.Sieber@telekom.de> * Don't disable systemd-journald-audit.socket on Suse it seems the socket doesn't exist on this OS Signed-off-by: Christoph Sieber <Christoph.Sieber@telekom.de> --------- Signed-off-by: Christoph Sieber <Christoph.Sieber@telekom.de> Co-authored-by: Christoph Sieber <Christoph.Sieber@telekom.de>
1 parent 9976169 commit 940ed98

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed

roles/os_hardening/handlers/main.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,3 +27,8 @@
2727
path: "{{ item }}"
2828
state: remounted
2929
loop: "{{ mountpoints_changed }}"
30+
31+
- name: Restart journald
32+
ansible.builtin.systemd:
33+
name: systemd-journald.service
34+
state: restarted

roles/os_hardening/tasks/auditd.yml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,3 +16,15 @@
1616
- Restart auditd via service
1717
- Restart auditd via systemd
1818
tags: auditd
19+
20+
- name: Disable systemd-journald.audit
21+
when:
22+
- ansible_facts.os_family != 'Suse' # socket doesn't seem to exist on suse
23+
ansible.builtin.systemd:
24+
name: systemd-journald-audit.socket
25+
state: stopped
26+
enabled: false
27+
masked: true
28+
notify:
29+
- Restart journald
30+
tags: auditd

0 commit comments

Comments
 (0)