How to stop and disable auditd on RHEL 7

How to stop and disable auditd on RHEL 7?

Solution Verified - Updated -

Environment

Red Hat Enterprise Linux 7

Issue

Disclaimer: Links contained herein to external website(s) are provided for convenience only. Red Hat has not reviewed the links and is not responsible for the content or its availability. The inclusion of any link to an external website does not imply endorsement by Red Hat of the website or their entities, products or services. You agree that Red Hat is not responsible or liable for any loss or expenses that may result due to your use of (or reliance on) the external site or content.

How to stop and disable auditd on RHEL 7?

Resolution

Disable auditd temporarily (this will disable logging instantly but will not survive a reboot):

auditctl -e0

Disable auditd permanently (this will require a reboot):

systemctl disable auditd

Verification:

[root@dhcp182-79 ~]# auditctl -s
enabled 0     # <----- this means that auditd logging is disabled
failure 1
pid 478
rate_limit 0
backlog_limit 64
lost 0
backlog 0
loginuid_immutable 0 unlocked

Root Cause

auditd documentation

man auditd
(...)
       -e [0..2]
              Set  enabled  flag.  When  0  is passed, this can be used to temporarily disable
              auditing. When 1 is passed as an argument, it will enable auditing. To lock  the
              audit configuration so that it can't be changed, pass a 2 as the argument. Lock‐
              ing the configuration is intended to be the last command in audit.rules for any‐
              one  wishing  this feature to be active. Any attempt to change the configuration
              in this mode will be audited and denied. The configuration can only  be  changed
              by rebooting the machine.
5 (1)
Article Rating (1 Votes)
Rate this article
Attachments
There are no attachments for this article.
Comments
There are no comments for this article. Be the first to post a comment.
Full Name
Email Address
Security Code Security Code
Related Articles RSS Feed
RHCS6: Create a new Logical Volume / Global Filesystem 2 (GFS2)
Viewed 2154 times since Sun, Jun 3, 2018
Oracle Linux 7 – How to audit changes to a trusted file such as /etc/passwd or /etc/shadow
Viewed 2855 times since Wed, Jul 25, 2018
chrt command: Set / Manipulate Real Time Attributes of a Linux Process
Viewed 10898 times since Mon, Feb 17, 2020
RHEL: Force system to prompt for password in Single User mode
Viewed 7176 times since Sat, Jun 2, 2018
10 Linux nslookup Command Examples for DNS Lookup
Viewed 10132 times since Sun, Sep 30, 2018
12 Linux Rsync Options in Linux Explained
Viewed 11932 times since Wed, Oct 31, 2018
Fałszujemy rozpoznania skanerów #2
Viewed 2879 times since Mon, May 21, 2018
10 Linux cryptsetup Examples for LUKS Key Management (How to Add, Remove, Change, Reset LUKS encryption Key)
Viewed 5043 times since Tue, Jul 31, 2018
How to remove CTRL-M (^M) characters from a file in Linux
Viewed 2495 times since Thu, Feb 7, 2019
Linux Find Large Files
Viewed 2811 times since Mon, Oct 29, 2018