Technical Requirements
For this chapter, you'll need one or two VMs running a Linux distribution. You can use the smallest size if you want. The audit
daemon must be installed and, for the purpose of having audit system logs to analyze and understand, it's a good idea to install Apache and a MySQL/MariaDB server.
Here is an example in CentOS:
sudo yum groups install ''Basic Web Server'' sudo yum install mariadbmariadb-server sudo yum install setroubleshoot sudosystemctl enable --now apache2 sudosystemctl enable --now mariadb
auditd
gives in-depth details about your server performance and activity by using audit rules that can be modified based on your needs. To install audit
daemon, use the following:
sudo yum list audit audit-libs
On executing the preceding command, you'll get the following output:
Figure 11.1: Installing the audit daemon
If you can see the list of installed audit packages as shown previously...