List active Linux Audit rules
Build a paste-ready command, then review its compatibility and effects before running it.
read-onlyno known side effects Compatibility
LinuxVerified for Linux using posix, bash, zsh syntax.
Operational knowledgereview due 2027-01-20
Requirementsauditctlauditctl must be installed and available on PATH.
Version supportauditctl Current supported releasesVerified for linux using posix, bash, zsh syntax; consult compatibility notes for platform-specific differences.
Expected signals-w /etc/passwd -p wa -k identityRepresentative successful output; values vary with the selected target and system state.
Known errorsauditctl: command not foundauditctl is missing or is not available on PATH.
Verifyauditctl -lThe output matches the expected target and exits without an error.Rollback noteNot required: this command is read-only and does not change system state.
Command breakdown
01auditctlCommandRuns the auditctl stage of this one-liner.
02-lOptionConfigures auditctl with the -l option.
Example output
-w /etc/passwd -p wa -k identity
-a always,exit -F arch=b64 -S execve -F euid=0 -k privileged
Illustrative output — exact values vary by system and data.
Official sources