HEX
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/7.4.30
System: Linux iZj6c1151k3ad370bosnmsZ 3.10.0-1160.76.1.el7.x86_64 #1 SMP Wed Aug 10 16:21:17 UTC 2022 x86_64
User: root (0)
PHP: 7.4.30
Disabled: NONE
Upload Files
File: //usr/share/systemtap/examples/process/auditbt.stp
#!/usr/bin/stap

# Copyright (C) 2012 Red Hat, Inc.
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License version 2 as
# published by the Free Software Foundation.
#
# If suspecting particular processes triggering audit records,
# reinvoke with    stap -d /bin/program -d /lib/library --ldd

probe kernel.function("audit_log_end") {
      message_address = $ab->skb->head + 16; // audit data follows struct nlmsghdr
      message = kernel_string(message_address)
      printf("%s[%d] %s\n", execname(), tid(), message);
      print_ubacktrace();
}