Linux

Where Does auditd Store Rules and Logs?

auditd loads rules from /etc/audit/rules.d with the daemon config beside them and logs in /var/log/audit.

Last updated

auditd splits configuration across two spots. The daemon behavior lives in auditd.conf while watch rules live as files in rules.d merged at load. Logs accumulate in audit.log under /var/log/audit with rotation.

Immutable rules lock the set until reboot, which suits hardened servers. Test rule changes in permissive order before enforcing. Query logs with ausearch rather than grep for structured fields.

Where auditd stores this, by platform

Linux
/etc/audit/rules.d

Watch rules merged by augenrules at load. Daemon behavior sits in auditd.conf beside it. Logs land in /var/log/audit/audit.log.

Frequently asked questions

How do I watch a sensitive file?

Add a watch rule for the path in rules.d, reload with augenrules, and restart the daemon. Events appear in audit.log tagged by key. Query with ausearch using that key.

Why do audit logs fill the disk?

Broad watches on busy paths generate constant events. Narrow rules to sensitive files and set rotation limits in auditd.conf. Monitor space action fires before disks fill.

Notice an outdated path? Let us know.