1 Starting Test 1, iterate...
5 interp auid=unknown(848)
7 interp auid=unknown(848)
11 interp auid=unknown(848)
13 interp auid=unknown(848)
15 interp auid=unknown(848)
18 Starting Test 2, walk events, records, and fields...
20 record 1 of type 1006(LOGIN) has 5 fields
22 event time: 1143146623.787:142, host=?
26 auid=4294967295 (unset)
27 auid=848 (unknown(848))
30 record 1 of type 1300(SYSCALL) has 24 fields
32 event time: 1143146623.875:143, host=?
33 type=SYSCALL (SYSCALL)
34 arch=c000003e (x86_64)
35 syscall=188 (setxattr)
38 a0=7fffffa9a9f0 (0x7fffffa9a9f0)
39 a1=3958d11333 (0x3958d11333)
44 auid=848 (unknown(848))
55 exe="/bin/login" (/bin/login)
56 subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
59 record 1 of type 1112(USER_LOGIN) has 10 fields
61 event time: 1143146623.879:146, host=?
62 type=USER_LOGIN (USER_LOGIN)
65 auid=848 (unknown(848))
66 uid=848 (unknown(848))
67 exe="/bin/login" (/bin/login)
75 Starting Test 3, walk events, records of 1 buffer...
77 record 1 of type 1112(USER_LOGIN) has 10 fields
79 event time: 1143146623.879:146, host=?
83 Starting Test 4, walk events, records of 1 file...
85 record 1 of type 1400(AVC) has 11 fields
86 line=1 file=./test.log
87 event time: 1170021493.977:293, host=?
89 seresult=denied (denied)
90 seperms=read,write (read,write)
92 comm="pickup" (pickup)
93 name="maildrop" (maildrop)
95 ino=14911367 (14911367)
96 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
97 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
100 record 2 of type 1300(SYSCALL) has 26 fields
101 line=2 file=./test.log
102 event time: 1170021493.977:293, host=?
103 type=SYSCALL (SYSCALL)
104 arch=c000003e (x86_64)
107 exit=-13 (-13(Permission denied))
108 a0=5555665d91b0 (0x5555665d91b0)
109 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
110 a2=5555665d91b8 (0x5555665d91b8)
115 auid=4294967295 (unset)
116 uid=890 (unknown(890))
117 gid=890 (unknown(890))
118 euid=890 (unknown(890))
119 suid=890 (unknown(890))
120 fsuid=890 (unknown(890))
121 egid=890 (unknown(890))
122 sgid=890 (unknown(890))
123 fsgid=890 (unknown(890))
125 comm="pickup" (pickup)
126 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
127 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
130 record 3 of type 1307(CWD) has 2 fields
131 line=3 file=./test.log
132 event time: 1170021493.977:293, host=?
134 cwd="/var/spool/postfix" (/var/spool/postfix)
136 record 4 of type 1302(PATH) has 10 fields
137 line=4 file=./test.log
138 event time: 1170021493.977:293, host=?
141 name="maildrop" (maildrop)
142 inode=14911367 (14911367)
144 mode=040730 (dir,730)
145 ouid=890 (unknown(890))
146 ogid=891 (unknown(891))
148 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
150 event 2 has 1 records
151 record 1 of type 1101(USER_ACCT) has 11 fields
152 line=5 file=./test.log
153 event time: 1170021601.340:294, host=?
154 type=USER_ACCT (USER_ACCT)
157 auid=4294967295 (unset)
158 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
160 exe="/usr/sbin/crond" (/usr/sbin/crond)
164 res=success (success)
166 event 3 has 1 records
167 record 1 of type 1103(CRED_ACQ) has 11 fields
168 line=6 file=./test.log
169 event time: 1170021601.342:295, host=?
170 type=CRED_ACQ (CRED_ACQ)
173 auid=4294967295 (unset)
174 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
176 exe="/usr/sbin/crond" (/usr/sbin/crond)
180 res=success (success)
182 event 4 has 1 records
183 record 1 of type 1006(LOGIN) has 5 fields
184 line=7 file=./test.log
185 event time: 1170021601.343:296, host=?
189 auid=4294967295 (unset)
192 event 5 has 1 records
193 record 1 of type 1105(USER_START) has 11 fields
194 line=8 file=./test.log
195 event time: 1170021601.344:297, host=?
196 type=USER_START (USER_START)
200 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
202 exe="/usr/sbin/crond" (/usr/sbin/crond)
206 res=success (success)
208 event 6 has 1 records
209 record 1 of type 1104(CRED_DISP) has 11 fields
210 line=9 file=./test.log
211 event time: 1170021601.364:298, host=?
212 type=CRED_DISP (CRED_DISP)
216 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
218 exe="/usr/sbin/crond" (/usr/sbin/crond)
222 res=success (success)
224 event 7 has 1 records
225 record 1 of type 1106(USER_END) has 11 fields
226 line=10 file=./test.log
227 event time: 1170021601.366:299, host=?
228 type=USER_END (USER_END)
232 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
234 exe="/usr/sbin/crond" (/usr/sbin/crond)
238 res=success (success)
242 Starting Test 5, walk events, records of 2 files...
243 event 1 has 4 records
244 record 1 of type 1400(AVC) has 11 fields
246 event time: 1170021493.977:293, host=?
248 seresult=denied (denied)
249 seperms=read,write (read,write)
251 comm="pickup" (pickup)
252 name="maildrop" (maildrop)
254 ino=14911367 (14911367)
255 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
256 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
259 record 2 of type 1300(SYSCALL) has 26 fields
261 event time: 1170021493.977:293, host=?
262 type=SYSCALL (SYSCALL)
263 arch=c000003e (x86_64)
266 exit=-13 (-13(Permission denied))
267 a0=5555665d91b0 (0x5555665d91b0)
268 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
269 a2=5555665d91b8 (0x5555665d91b8)
274 auid=4294967295 (unset)
275 uid=890 (unknown(890))
276 gid=890 (unknown(890))
277 euid=890 (unknown(890))
278 suid=890 (unknown(890))
279 fsuid=890 (unknown(890))
280 egid=890 (unknown(890))
281 sgid=890 (unknown(890))
282 fsgid=890 (unknown(890))
284 comm="pickup" (pickup)
285 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
286 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
289 record 3 of type 1307(CWD) has 2 fields
291 event time: 1170021493.977:293, host=?
293 cwd="/var/spool/postfix" (/var/spool/postfix)
295 record 4 of type 1302(PATH) has 10 fields
297 event time: 1170021493.977:293, host=?
300 name="maildrop" (maildrop)
301 inode=14911367 (14911367)
303 mode=040730 (dir,730)
304 ouid=890 (unknown(890))
305 ogid=891 (unknown(891))
307 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
309 event 2 has 1 records
310 record 1 of type 1101(USER_ACCT) has 11 fields
312 event time: 1170021601.340:294, host=?
313 type=USER_ACCT (USER_ACCT)
316 auid=4294967295 (unset)
317 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
319 exe="/usr/sbin/crond" (/usr/sbin/crond)
323 res=success (success)
325 event 3 has 1 records
326 record 1 of type 1103(CRED_ACQ) has 11 fields
328 event time: 1170021601.342:295, host=?
329 type=CRED_ACQ (CRED_ACQ)
332 auid=4294967295 (unset)
333 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
335 exe="/usr/sbin/crond" (/usr/sbin/crond)
339 res=success (success)
341 event 4 has 1 records
342 record 1 of type 1006(LOGIN) has 5 fields
344 event time: 1170021601.343:296, host=?
348 auid=4294967295 (unset)
351 event 5 has 1 records
352 record 1 of type 1105(USER_START) has 11 fields
354 event time: 1170021601.344:297, host=?
355 type=USER_START (USER_START)
359 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
361 exe="/usr/sbin/crond" (/usr/sbin/crond)
365 res=success (success)
367 event 6 has 1 records
368 record 1 of type 1104(CRED_DISP) has 11 fields
370 event time: 1170021601.364:298, host=?
371 type=CRED_DISP (CRED_DISP)
375 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
377 exe="/usr/sbin/crond" (/usr/sbin/crond)
381 res=success (success)
383 event 7 has 1 records
384 record 1 of type 1106(USER_END) has 11 fields
385 line=10 file=test.log
386 event time: 1170021601.366:299, host=?
387 type=USER_END (USER_END)
391 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
393 exe="/usr/sbin/crond" (/usr/sbin/crond)
397 res=success (success)
399 event 8 has 4 records
400 record 1 of type 1400(AVC) has 11 fields
401 line=1 file=test2.log
402 event time: 1170021493.977:293, host=?
404 seresult=denied (denied)
407 comm="pickup" (pickup)
408 name="maildrop" (maildrop)
410 ino=14911367 (14911367)
411 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
412 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
415 record 2 of type 1300(SYSCALL) has 26 fields
416 line=2 file=test2.log
417 event time: 1170021493.977:293, host=?
418 type=SYSCALL (SYSCALL)
419 arch=c000003e (x86_64)
422 exit=-13 (-13(Permission denied))
423 a0=5555665d91b0 (0x5555665d91b0)
424 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
425 a2=5555665d91b8 (0x5555665d91b8)
430 auid=4294967295 (unset)
431 uid=890 (unknown(890))
432 gid=890 (unknown(890))
433 euid=890 (unknown(890))
434 suid=890 (unknown(890))
435 fsuid=890 (unknown(890))
436 egid=890 (unknown(890))
437 sgid=890 (unknown(890))
438 fsgid=890 (unknown(890))
440 comm="pickup" (pickup)
441 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
442 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
445 record 3 of type 1307(CWD) has 2 fields
446 line=3 file=test2.log
447 event time: 1170021493.977:293, host=?
449 cwd="/var/spool/postfix" (/var/spool/postfix)
451 record 4 of type 1302(PATH) has 10 fields
452 line=4 file=test2.log
453 event time: 1170021493.977:293, host=?
456 name="maildrop" (maildrop)
457 inode=14911367 (14911367)
459 mode=040730 (dir,730)
460 ouid=890 (unknown(890))
461 ogid=891 (unknown(891))
463 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
465 event 9 has 1 records
466 record 1 of type 1101(USER_ACCT) has 11 fields
467 line=5 file=test2.log
468 event time: 1170021601.340:294, host=?
469 type=USER_ACCT (USER_ACCT)
472 auid=4294967295 (unset)
473 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
475 exe="/usr/sbin/crond" (/usr/sbin/crond)
479 res=success (success)
481 event 10 has 1 records
482 record 1 of type 1103(CRED_ACQ) has 11 fields
483 line=6 file=test2.log
484 event time: 1170021601.342:295, host=?
485 type=CRED_ACQ (CRED_ACQ)
488 auid=4294967295 (unset)
489 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
491 exe="/usr/sbin/crond" (/usr/sbin/crond)
495 res=success (success)
497 event 11 has 1 records
498 record 1 of type 1006(LOGIN) has 5 fields
499 line=7 file=test2.log
500 event time: 1170021601.343:296, host=?
504 auid=4294967295 (unset)
507 event 12 has 1 records
508 record 1 of type 1105(USER_START) has 11 fields
509 line=8 file=test2.log
510 event time: 1170021601.344:297, host=?
511 type=USER_START (USER_START)
515 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
517 exe="/usr/sbin/crond" (/usr/sbin/crond)
521 res=success (success)
523 event 13 has 1 records
524 record 1 of type 1104(CRED_DISP) has 11 fields
525 line=9 file=test2.log
526 event time: 1170021601.364:298, host=?
527 type=CRED_DISP (CRED_DISP)
531 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
533 exe="/usr/sbin/crond" (/usr/sbin/crond)
537 res=success (success)
539 event 14 has 1 records
540 record 1 of type 1106(USER_END) has 11 fields
541 line=10 file=test2.log
542 event time: 1170021601.366:299, host=?
543 type=USER_END (USER_END)
547 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
549 exe="/usr/sbin/crond" (/usr/sbin/crond)
553 res=success (success)
557 Starting Test 6, search...
558 auid = 500 not found...which is correct
559 auid exists...which is correct
560 Testing BUFFER_ARRAY, stop on field
562 Testing BUFFER_ARRAY, stop on record
564 Testing BUFFER_ARRAY, stop on event
566 Testing test.log, stop on field
567 Found auid = 4294967295
568 Testing test.log, stop on record
570 Testing test.log, stop on event
574 Starting Test 7, compound search...
575 Found type = USER_START
579 Starting Test 8, regex search...
582 Doing regex wildcard search...
583 Found type = USER_LOGIN
586 Starting Test 9, buffer feed...
587 event 1 has 1 records
588 record 1 of type 1006(LOGIN) has 5 fields
590 event time: 1143146623.787:142, host=?
594 auid=4294967295 (unset)
595 auid=848 (unknown(848))
597 event 2 has 1 records
598 record 1 of type 1300(SYSCALL) has 24 fields
600 event time: 1143146623.875:143, host=?
601 type=SYSCALL (SYSCALL)
602 arch=c000003e (x86_64)
603 syscall=188 (setxattr)
606 a0=7fffffa9a9f0 (0x7fffffa9a9f0)
607 a1=3958d11333 (0x3958d11333)
612 auid=848 (unknown(848))
623 exe="/bin/login" (/bin/login)
624 subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
626 event 3 has 1 records
627 record 1 of type 1112(USER_LOGIN) has 10 fields
629 event time: 1143146623.879:146, host=?
630 type=USER_LOGIN (USER_LOGIN)
633 auid=848 (unknown(848))
634 uid=848 (unknown(848))
635 exe="/bin/login" (/bin/login)
639 res=success (success)
643 Starting Test 10, file feed...
644 event 1 has 4 records
645 record 1 of type 1400(AVC) has 11 fields
647 event time: 1170021493.977:293, host=?
649 seresult=denied (denied)
650 seperms=read,write (read,write)
652 comm="pickup" (pickup)
653 name="maildrop" (maildrop)
655 ino=14911367 (14911367)
656 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
657 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
660 record 2 of type 1300(SYSCALL) has 26 fields
662 event time: 1170021493.977:293, host=?
663 type=SYSCALL (SYSCALL)
664 arch=c000003e (x86_64)
667 exit=-13 (-13(Permission denied))
668 a0=5555665d91b0 (0x5555665d91b0)
669 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
670 a2=5555665d91b8 (0x5555665d91b8)
675 auid=4294967295 (unset)
676 uid=890 (unknown(890))
677 gid=890 (unknown(890))
678 euid=890 (unknown(890))
679 suid=890 (unknown(890))
680 fsuid=890 (unknown(890))
681 egid=890 (unknown(890))
682 sgid=890 (unknown(890))
683 fsgid=890 (unknown(890))
685 comm="pickup" (pickup)
686 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
687 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
690 record 3 of type 1307(CWD) has 2 fields
692 event time: 1170021493.977:293, host=?
694 cwd="/var/spool/postfix" (/var/spool/postfix)
696 record 4 of type 1302(PATH) has 10 fields
698 event time: 1170021493.977:293, host=?
701 name="maildrop" (maildrop)
702 inode=14911367 (14911367)
704 mode=040730 (dir,730)
705 ouid=890 (unknown(890))
706 ogid=891 (unknown(891))
708 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
710 event 2 has 1 records
711 record 1 of type 1101(USER_ACCT) has 11 fields
713 event time: 1170021601.340:294, host=?
714 type=USER_ACCT (USER_ACCT)
717 auid=4294967295 (unset)
718 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
720 exe="/usr/sbin/crond" (/usr/sbin/crond)
724 res=success (success)
726 event 3 has 1 records
727 record 1 of type 1103(CRED_ACQ) has 11 fields
729 event time: 1170021601.342:295, host=?
730 type=CRED_ACQ (CRED_ACQ)
733 auid=4294967295 (unset)
734 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
736 exe="/usr/sbin/crond" (/usr/sbin/crond)
740 res=success (success)
742 event 4 has 1 records
743 record 1 of type 1006(LOGIN) has 5 fields
745 event time: 1170021601.343:296, host=?
749 auid=4294967295 (unset)
752 event 5 has 1 records
753 record 1 of type 1105(USER_START) has 11 fields
755 event time: 1170021601.344:297, host=?
756 type=USER_START (USER_START)
760 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
762 exe="/usr/sbin/crond" (/usr/sbin/crond)
766 res=success (success)
768 event 6 has 1 records
769 record 1 of type 1104(CRED_DISP) has 11 fields
771 event time: 1170021601.364:298, host=?
772 type=CRED_DISP (CRED_DISP)
776 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
778 exe="/usr/sbin/crond" (/usr/sbin/crond)
782 res=success (success)
784 event 7 has 1 records
785 record 1 of type 1106(USER_END) has 11 fields
787 event time: 1170021601.366:299, host=?
788 type=USER_END (USER_END)
792 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
794 exe="/usr/sbin/crond" (/usr/sbin/crond)
798 res=success (success)
802 Finished non-admin tests