Log de amostra:
type=SERVICE_START msg=audit(1497515461.023:2020433): pid=1 uid=0 auid=4294967295 ses=4294967295 msg=' comm="systemd-tmpfiles-clean" exe="/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
type=SERVICE_STOP msg=audit(1497515461.023:2020434): pid=1 uid=0 auid=4294967295 ses=4294967295 msg=' comm="systemd-tmpfiles-clean" exe="/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
O que é tão específico para o comando systemd-tmpfiles-clean
que faz com que ele reinicie o daemon de auditoria?
Tags services daemon linux-audit