Ceci est une ancienne révision du document !
~~CLOSETOC~~
Auditd
<note warning>root</note>
Prérequis
- apt-get install -y apt-transport-https dirmngr #openjdk-8-jdk
Installation Auditd
- apt-get install -y auditd audispd-plugins
Configuration des règles
# TODO
# Lynis ?
Installation ElasticSearch
- wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
- echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | tee -a /etc/apt/sources.list.d/elastic-7.x.list
- apt-get update
- apt-get install elasticsearch
Démarrage auto
- /bin/systemctl daemon-reload
- /bin/systemctl enable elasticsearch.service

Discussion