Linux Audit Logs record detailed information about system events, user activities, and security-related actions. They are essential for monitoring system integrity, detecting unauthorized access, and ensuring compliance with security policies and regulations.
This integration provides enrichment and visualization for various log types, including:
Mandatory Access Control (MAC) configurations and status
MAC policies
Role assignments, removals, and user role changes
Audit configuration changes and audit daemon events (such as aborts, configuration changes)
User authentication events
User account credential modifications
User and group management activities
SELinux user errors
Access Vector Cache (AVC) logs
It supports these logs across Red Hat, Ubuntu, and CentOS Linux operating systems.
This integration collects Linux audit logs and sends them to Datadog for analysis. It provides visual insights through out-of-the-box dashboards and the Log Explorer, and helps monitor and respond to security threats using ready-to-use Cloud SIEM detection rules.