npamnani
10/24/2019, 4:43 AMtimb
10/24/2019, 4:51 AM[ 984.078179] Call Trace:
[ 984.080639] __schedule+0x2bc/0x89b
[ 984.084134] schedule+0x36/0x7c
[ 984.087280] schedule_preempt_disabled+0xe/0x10
[ 984.091812] __mutex_lock.isra.5+0x20c/0x634
[ 984.096089] ? release_sock+0x8f/0x94
[ 1106.935142] INFO: task systemd:1 blocked for more than 120 seconds.
npamnani
10/24/2019, 7:42 AMtimb
10/24/2019, 5:15 PM[
{"name":"audit_allow_config","value":"true"},
{"name":"audit_allow_fim_events","value":"false"},
{"name":"audit_allow_fork_process_events","value":"false"},
{"name":"audit_allow_process_events","value":"true"},
{"name":"audit_allow_selinux_events","value":"false"},
{"name":"audit_allow_sockets","value":"true"},
{"name":"audit_allow_unix","value":"false"},
{"name":"audit_allow_user_events","value":"true"},
{"name":"audit_debug","value":"false"},
{"name":"audit_fim_debug","value":"false"},
{"name":"audit_fim_show_accesses","value":"false"},
{"name":"audit_force_reconfigure","value":"false"},
{"name":"audit_force_unconfigure","value":"false"},
{"name":"audit_persist","value":"true"},
{"name":"audit_show_partial_fim_events","value":"false"},
{"name":"audit_show_untracked_res_warnings","value":"false"},
{"name":"disable_audit","value":"false"}
]
$ sudo auditctl -s
enabled 1
failure 0
pid 26178
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
npamnani
10/24/2019, 6:09 PMtheopolis
10/24/2019, 6:40 PMtimb
10/24/2019, 7:03 PM$ sudo auditctl -l;echo; sudo auditctl -s
-a always,exit -S connect
-a always,exit -S bind
-a always,exit -S execve
-a always,exit -S execveat
enabled 1
failure 0
pid 19405
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
osquery stopped:
$ sudo auditctl -l;echo; sudo auditctl -s
No rules
enabled 0
failure 1
pid 19405
rate_limit 0
backlog_limit 0
lost 0
backlog 0
loginuid_immutable 0 unlocked
$ sudo auditctl -l;echo; sudo auditctl -s
-a always,exit -S connect
-a always,exit -S bind
-a always,exit -S execve
-a always,exit -S execveat
enabled 1
failure 0
pid 32732
rate_limit 0
backlog_limit 4096
lost 0
backlog 0
loginuid_immutable 0 unlocked
npamnani
10/24/2019, 7:46 PMtimb
10/24/2019, 7:52 PMnpamnani
10/24/2019, 8:06 PMtimb
10/24/2019, 8:07 PMnpamnani
10/24/2019, 8:09 PMtimb
10/24/2019, 8:21 PMnpamnani
10/24/2019, 8:22 PMtimb
10/24/2019, 8:22 PMnpamnani
10/24/2019, 8:22 PMtimb
10/24/2019, 8:25 PMnpamnani
10/24/2019, 8:25 PMtimb
10/24/2019, 8:28 PMtheopolis
10/24/2019, 8:37 PMIvanlei
10/25/2019, 4:46 PMnpamnani
10/27/2019, 7:30 AM