1 Starting Test 1, iterate...
5 interp auid=unknown(848)
7 interp auid=unknown(848)
10 Starting Test 2, walk events, records, and fields...
12 record 1 of type 1006(LOGIN) has 5 fields
14 event time: 1143146623.787:142, host=(null)
18 auid=4294967295 (unset)
19 auid=848 (unknown(848))
22 record 1 of type 1300(SYSCALL) has 24 fields
24 event time: 1143146623.875:143, host=(null)
25 type=SYSCALL (SYSCALL)
26 arch=c000003e (x86_64)
27 syscall=188 (setxattr)
30 a0=7fffffa9a9f0 (0x7fffffa9a9f0)
31 a1=3958d11333 (0x3958d11333)
36 auid=848 (unknown(848))
47 exe="/bin/login" (/bin/login)
48 subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
51 record 1 of type 1112(USER_LOGIN) has 10 fields
53 event time: 1143146623.879:146, host=(null)
54 type=USER_LOGIN (USER_LOGIN)
57 auid=848 (unknown(848))
58 uid=848 (unknown(848))
59 exe="/bin/login" (/bin/login)
67 Starting Test 3, walk events, records of 1 buffer...
69 record 1 of type 1112(USER_LOGIN) has 10 fields
71 event time: 1143146623.879:146, host=(null)
75 Starting Test 4, walk events, records of 1 file...
77 record 1 of type 1400(AVC) has 11 fields
79 event time: 1170021493.977:293, host=(null)
81 seresult=denied (denied)
82 seperms=read,write (read,write)
84 comm="pickup" (pickup)
85 name="maildrop" (maildrop)
87 ino=14911367 (14911367)
88 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
89 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
92 record 2 of type 1300(SYSCALL) has 26 fields
94 event time: 1170021493.977:293, host=(null)
95 type=SYSCALL (SYSCALL)
96 arch=c000003e (x86_64)
99 exit=-13 (-13(Permission denied))
100 a0=5555665d91b0 (0x5555665d91b0)
101 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
102 a2=5555665d91b8 (0x5555665d91b8)
107 auid=4294967295 (unset)
108 uid=890 (unknown(890))
109 gid=890 (unknown(890))
110 euid=890 (unknown(890))
111 suid=890 (unknown(890))
112 fsuid=890 (unknown(890))
113 egid=890 (unknown(890))
114 sgid=890 (unknown(890))
115 fsgid=890 (unknown(890))
117 comm="pickup" (pickup)
118 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
119 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
122 record 3 of type 1307(CWD) has 2 fields
124 event time: 1170021493.977:293, host=(null)
126 cwd="/var/spool/postfix" (/var/spool/postfix)
128 record 4 of type 1302(PATH) has 10 fields
130 event time: 1170021493.977:293, host=(null)
133 name="maildrop" (maildrop)
134 inode=14911367 (14911367)
136 mode=040730 (dir,730)
137 ouid=890 (unknown(890))
138 ogid=891 (unknown(891))
140 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
142 event 2 has 1 records
143 record 1 of type 1101(USER_ACCT) has 11 fields
145 event time: 1170021601.340:294, host=(null)
146 type=USER_ACCT (USER_ACCT)
149 auid=4294967295 (unset)
150 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
152 exe="/usr/sbin/crond" (/usr/sbin/crond)
156 res=success (success)
158 event 3 has 1 records
159 record 1 of type 1103(CRED_ACQ) has 11 fields
161 event time: 1170021601.342:295, host=(null)
162 type=CRED_ACQ (CRED_ACQ)
165 auid=4294967295 (unset)
166 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
168 exe="/usr/sbin/crond" (/usr/sbin/crond)
172 res=success (success)
174 event 4 has 1 records
175 record 1 of type 1006(LOGIN) has 5 fields
177 event time: 1170021601.343:296, host=(null)
181 auid=4294967295 (unset)
184 event 5 has 1 records
185 record 1 of type 1105(USER_START) has 11 fields
187 event time: 1170021601.344:297, host=(null)
188 type=USER_START (USER_START)
192 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
194 exe="/usr/sbin/crond" (/usr/sbin/crond)
198 res=success (success)
200 event 6 has 1 records
201 record 1 of type 1104(CRED_DISP) has 11 fields
203 event time: 1170021601.364:298, host=(null)
204 type=CRED_DISP (CRED_DISP)
208 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
210 exe="/usr/sbin/crond" (/usr/sbin/crond)
214 res=success (success)
216 event 7 has 1 records
217 record 1 of type 1106(USER_END) has 11 fields
218 line=10 file=test.log
219 event time: 1170021601.366:299, host=(null)
220 type=USER_END (USER_END)
224 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
226 exe="/usr/sbin/crond" (/usr/sbin/crond)
230 res=success (success)
234 Starting Test 5, walk events, records of 2 files...
235 event 1 has 4 records
236 record 1 of type 1400(AVC) has 11 fields
238 event time: 1170021493.977:293, host=(null)
240 seresult=denied (denied)
241 seperms=read,write (read,write)
243 comm="pickup" (pickup)
244 name="maildrop" (maildrop)
246 ino=14911367 (14911367)
247 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
248 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
251 record 2 of type 1300(SYSCALL) has 26 fields
253 event time: 1170021493.977:293, host=(null)
254 type=SYSCALL (SYSCALL)
255 arch=c000003e (x86_64)
258 exit=-13 (-13(Permission denied))
259 a0=5555665d91b0 (0x5555665d91b0)
260 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
261 a2=5555665d91b8 (0x5555665d91b8)
266 auid=4294967295 (unset)
267 uid=890 (unknown(890))
268 gid=890 (unknown(890))
269 euid=890 (unknown(890))
270 suid=890 (unknown(890))
271 fsuid=890 (unknown(890))
272 egid=890 (unknown(890))
273 sgid=890 (unknown(890))
274 fsgid=890 (unknown(890))
276 comm="pickup" (pickup)
277 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
278 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
281 record 3 of type 1307(CWD) has 2 fields
283 event time: 1170021493.977:293, host=(null)
285 cwd="/var/spool/postfix" (/var/spool/postfix)
287 record 4 of type 1302(PATH) has 10 fields
289 event time: 1170021493.977:293, host=(null)
292 name="maildrop" (maildrop)
293 inode=14911367 (14911367)
295 mode=040730 (dir,730)
296 ouid=890 (unknown(890))
297 ogid=891 (unknown(891))
299 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
301 event 2 has 1 records
302 record 1 of type 1101(USER_ACCT) has 11 fields
304 event time: 1170021601.340:294, host=(null)
305 type=USER_ACCT (USER_ACCT)
308 auid=4294967295 (unset)
309 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
311 exe="/usr/sbin/crond" (/usr/sbin/crond)
315 res=success (success)
317 event 3 has 1 records
318 record 1 of type 1103(CRED_ACQ) has 11 fields
320 event time: 1170021601.342:295, host=(null)
321 type=CRED_ACQ (CRED_ACQ)
324 auid=4294967295 (unset)
325 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
327 exe="/usr/sbin/crond" (/usr/sbin/crond)
331 res=success (success)
333 event 4 has 1 records
334 record 1 of type 1006(LOGIN) has 5 fields
336 event time: 1170021601.343:296, host=(null)
340 auid=4294967295 (unset)
343 event 5 has 1 records
344 record 1 of type 1105(USER_START) has 11 fields
346 event time: 1170021601.344:297, host=(null)
347 type=USER_START (USER_START)
351 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
353 exe="/usr/sbin/crond" (/usr/sbin/crond)
357 res=success (success)
359 event 6 has 1 records
360 record 1 of type 1104(CRED_DISP) has 11 fields
362 event time: 1170021601.364:298, host=(null)
363 type=CRED_DISP (CRED_DISP)
367 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
369 exe="/usr/sbin/crond" (/usr/sbin/crond)
373 res=success (success)
375 event 7 has 1 records
376 record 1 of type 1106(USER_END) has 11 fields
377 line=10 file=test.log
378 event time: 1170021601.366:299, host=(null)
379 type=USER_END (USER_END)
383 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
385 exe="/usr/sbin/crond" (/usr/sbin/crond)
389 res=success (success)
391 event 8 has 4 records
392 record 1 of type 1400(AVC) has 11 fields
393 line=1 file=test2.log
394 event time: 1170021493.977:293, host=(null)
396 seresult=denied (denied)
399 comm="pickup" (pickup)
400 name="maildrop" (maildrop)
402 ino=14911367 (14911367)
403 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
404 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
407 record 2 of type 1300(SYSCALL) has 26 fields
408 line=2 file=test2.log
409 event time: 1170021493.977:293, host=(null)
410 type=SYSCALL (SYSCALL)
411 arch=c000003e (x86_64)
414 exit=-13 (-13(Permission denied))
415 a0=5555665d91b0 (0x5555665d91b0)
416 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
417 a2=5555665d91b8 (0x5555665d91b8)
422 auid=4294967295 (unset)
423 uid=890 (unknown(890))
424 gid=890 (unknown(890))
425 euid=890 (unknown(890))
426 suid=890 (unknown(890))
427 fsuid=890 (unknown(890))
428 egid=890 (unknown(890))
429 sgid=890 (unknown(890))
430 fsgid=890 (unknown(890))
432 comm="pickup" (pickup)
433 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
434 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
437 record 3 of type 1307(CWD) has 2 fields
438 line=3 file=test2.log
439 event time: 1170021493.977:293, host=(null)
441 cwd="/var/spool/postfix" (/var/spool/postfix)
443 record 4 of type 1302(PATH) has 10 fields
444 line=4 file=test2.log
445 event time: 1170021493.977:293, host=(null)
448 name="maildrop" (maildrop)
449 inode=14911367 (14911367)
451 mode=040730 (dir,730)
452 ouid=890 (unknown(890))
453 ogid=891 (unknown(891))
455 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
457 event 9 has 1 records
458 record 1 of type 1101(USER_ACCT) has 11 fields
459 line=5 file=test2.log
460 event time: 1170021601.340:294, host=(null)
461 type=USER_ACCT (USER_ACCT)
464 auid=4294967295 (unset)
465 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
467 exe="/usr/sbin/crond" (/usr/sbin/crond)
471 res=success (success)
473 event 10 has 1 records
474 record 1 of type 1103(CRED_ACQ) has 11 fields
475 line=6 file=test2.log
476 event time: 1170021601.342:295, host=(null)
477 type=CRED_ACQ (CRED_ACQ)
480 auid=4294967295 (unset)
481 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
483 exe="/usr/sbin/crond" (/usr/sbin/crond)
487 res=success (success)
489 event 11 has 1 records
490 record 1 of type 1006(LOGIN) has 5 fields
491 line=7 file=test2.log
492 event time: 1170021601.343:296, host=(null)
496 auid=4294967295 (unset)
499 event 12 has 1 records
500 record 1 of type 1105(USER_START) has 11 fields
501 line=8 file=test2.log
502 event time: 1170021601.344:297, host=(null)
503 type=USER_START (USER_START)
507 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
509 exe="/usr/sbin/crond" (/usr/sbin/crond)
513 res=success (success)
515 event 13 has 1 records
516 record 1 of type 1104(CRED_DISP) has 11 fields
517 line=9 file=test2.log
518 event time: 1170021601.364:298, host=(null)
519 type=CRED_DISP (CRED_DISP)
523 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
525 exe="/usr/sbin/crond" (/usr/sbin/crond)
529 res=success (success)
531 event 14 has 1 records
532 record 1 of type 1106(USER_END) has 11 fields
533 line=10 file=test2.log
534 event time: 1170021601.366:299, host=(null)
535 type=USER_END (USER_END)
539 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
541 exe="/usr/sbin/crond" (/usr/sbin/crond)
545 res=success (success)
549 Starting Test 6, search...
550 auid = 500 not found...which is correct
551 auid exists...which is correct
552 Testing BUFFER_ARRAY, stop on field
554 Testing BUFFER_ARRAY, stop on record
556 Testing BUFFER_ARRAY, stop on event
558 Testing test.log, stop on field
559 Found auid = 4294967295
560 Testing test.log, stop on record
562 Testing test.log, stop on event
566 Starting Test 7, compound search...
567 Found type = USER_START
571 Starting Test 8, regex search...
576 Starting Test 9, buffer feed...
577 event 1 has 1 records
578 record 1 of type 1006(LOGIN) has 5 fields
580 event time: 1143146623.787:142, host=(null)
584 auid=4294967295 (unset)
585 auid=848 (unknown(848))
587 event 2 has 1 records
588 record 1 of type 1300(SYSCALL) has 24 fields
590 event time: 1143146623.875:143, host=(null)
591 type=SYSCALL (SYSCALL)
592 arch=c000003e (x86_64)
593 syscall=188 (setxattr)
596 a0=7fffffa9a9f0 (0x7fffffa9a9f0)
597 a1=3958d11333 (0x3958d11333)
602 auid=848 (unknown(848))
613 exe="/bin/login" (/bin/login)
614 subj=system_u:system_r:local_login_t:s0-s0:c0.c255 (system_u:system_r:local_login_t:s0-s0:c0.c255)
616 event 3 has 1 records
617 record 1 of type 1112(USER_LOGIN) has 10 fields
619 event time: 1143146623.879:146, host=(null)
620 type=USER_LOGIN (USER_LOGIN)
623 auid=848 (unknown(848))
624 uid=848 (unknown(848))
625 exe="/bin/login" (/bin/login)
629 res=success (success)
633 Starting Test 10, file feed...
634 event 1 has 4 records
635 record 1 of type 1400(AVC) has 11 fields
637 event time: 1170021493.977:293, host=(null)
639 seresult=denied (denied)
640 seperms=read,write (read,write)
642 comm="pickup" (pickup)
643 name="maildrop" (maildrop)
645 ino=14911367 (14911367)
646 scontext=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
647 tcontext=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
650 record 2 of type 1300(SYSCALL) has 26 fields
652 event time: 1170021493.977:293, host=(null)
653 type=SYSCALL (SYSCALL)
654 arch=c000003e (x86_64)
657 exit=-13 (-13(Permission denied))
658 a0=5555665d91b0 (0x5555665d91b0)
659 a1=10800 (O_RDONLY|O_NONBLOCK|O_DIRECTORY)
660 a2=5555665d91b8 (0x5555665d91b8)
665 auid=4294967295 (unset)
666 uid=890 (unknown(890))
667 gid=890 (unknown(890))
668 euid=890 (unknown(890))
669 suid=890 (unknown(890))
670 fsuid=890 (unknown(890))
671 egid=890 (unknown(890))
672 sgid=890 (unknown(890))
673 fsgid=890 (unknown(890))
675 comm="pickup" (pickup)
676 exe="/usr/libexec/postfix/pickup" (/usr/libexec/postfix/pickup)
677 subj=system_u:system_r:postfix_pickup_t:s0 (system_u:system_r:postfix_pickup_t:s0)
680 record 3 of type 1307(CWD) has 2 fields
682 event time: 1170021493.977:293, host=(null)
684 cwd="/var/spool/postfix" (/var/spool/postfix)
686 record 4 of type 1302(PATH) has 10 fields
688 event time: 1170021493.977:293, host=(null)
691 name="maildrop" (maildrop)
692 inode=14911367 (14911367)
694 mode=040730 (dir,730)
695 ouid=890 (unknown(890))
696 ogid=891 (unknown(891))
698 obj=system_u:object_r:postfix_spool_maildrop_t:s0 (system_u:object_r:postfix_spool_maildrop_t:s0)
700 event 2 has 1 records
701 record 1 of type 1101(USER_ACCT) has 11 fields
703 event time: 1170021601.340:294, host=(null)
704 type=USER_ACCT (USER_ACCT)
707 auid=4294967295 (unset)
708 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
710 exe="/usr/sbin/crond" (/usr/sbin/crond)
714 res=success (success)
716 event 3 has 1 records
717 record 1 of type 1103(CRED_ACQ) has 11 fields
719 event time: 1170021601.342:295, host=(null)
720 type=CRED_ACQ (CRED_ACQ)
723 auid=4294967295 (unset)
724 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
726 exe="/usr/sbin/crond" (/usr/sbin/crond)
730 res=success (success)
732 event 4 has 1 records
733 record 1 of type 1006(LOGIN) has 5 fields
735 event time: 1170021601.343:296, host=(null)
739 auid=4294967295 (unset)
742 event 5 has 1 records
743 record 1 of type 1105(USER_START) has 11 fields
745 event time: 1170021601.344:297, host=(null)
746 type=USER_START (USER_START)
750 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
752 exe="/usr/sbin/crond" (/usr/sbin/crond)
756 res=success (success)
758 event 6 has 1 records
759 record 1 of type 1104(CRED_DISP) has 11 fields
761 event time: 1170021601.364:298, host=(null)
762 type=CRED_DISP (CRED_DISP)
766 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
768 exe="/usr/sbin/crond" (/usr/sbin/crond)
772 res=success (success)
774 event 7 has 1 records
775 record 1 of type 1106(USER_END) has 11 fields
777 event time: 1170021601.366:299, host=(null)
778 type=USER_END (USER_END)
782 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 (system_u:system_r:crond_t:s0-s0:c0.c1023)
784 exe="/usr/sbin/crond" (/usr/sbin/crond)
788 res=success (success)
792 Finished non-admin tests