# man > AUSEARCH(8)

[_AUSEARCH_(8)](https://www.chedong.com/phpMan.php/man/AUSEARCH/8/markdown)                        System Administration Utilities                       [_AUSEARCH_(8)](https://www.chedong.com/phpMan.php/man/AUSEARCH/8/markdown)

## NAME
       ausearch - a tool to query audit daemon logs

## SYNOPSIS
       **ausearch **[_options_]

## DESCRIPTION
       **ausearch  **is  a tool that can query the audit daemon logs based for events based on different
       search criteria. The ausearch utility can also take input from stdin as long as the input  is
       the  raw  log  data.  Each  commandline  option  given forms an "and" statement. For example,
       searching with **-m **and **-ui **means return events that have both the requested type and match the
       user id given. An exception is the **-m  **and **-n **options; multiple record types  and  nodes  are
       allowed in a search which will return any matching node and record.

       It  should also be noted that each syscall excursion from user space into the kernel and back
       into user space has one event ID that is unique. Any auditable event that is triggered during
       this trip share this ID so that they may be correlated.

       Different parts of the kernel may add supplemental records. For example, an  audit  event  on
       the  syscall  "open" will also cause the kernel to emit a PATH record with the file name. The
       ausearch utility will present all records that make up one event together.  This  could  mean
       that  even  though you search for a specific kind of record, the resulting events may contain
       SYSCALL records.

       Also be aware that not all record types have the requested information. For example,  a  PATH
       record does not have a hostname or a loginuid.


## OPTIONS
### -a --event _
              Search  for an event based on the given _event_ _ID_. Messages always start with something
              like msg=audit(1116360555.329:2401771). The event ID is the number after the ':'.  All
              audit  events  that  are  recorded  from one application's syscall have the same audit
              event ID. A second syscall made by the same application will have  a  different  event
              ID. This way they are unique.

       **--arch _**CPU_
              Search  for  events based on a specific CPU architecture.  If you do not know the arch
              of your machine but you want to use the 32 bit syscall table and your machine supports
              32 bits, you can also use **b32 **for the arch. The same applies to the 64 bit syscall ta‐
              ble, you can use **b64.  **The arch of your machine can be found by doing 'uname -m'.

### -c --comm _
              Search for an event based on the given _comm_ _name_. The comm name  is  the  executable's
              name from the task structure.

### --debug
              Write malformed events that are skipped to stderr.

       **--checkpoint _**checkpoint-file_
              Checkpoint the output between successive invocations of ausearch such that only events
              not previously output will print in subsequent invocations.

              An  auditd  event  is made up of one or more records. When processing events, ausearch
              defines events as either complete or in-complete.  A complete event is either a single
              record event or one whose event time occurred 2 seconds in the past  compared  to  the
              event being currently processed.

              A  checkpoint  is achieved by recording the last completed event output along with the
              device number and inode of the file the last completed event appeared  in  _checkpoint-_
              _file_.  On  a  subsequent invocation, ausearch will load this checkpoint data and as it
              processes the log files, it will discard all complete  events  until  it  matches  the
              checkpointed one. At this point, it will start outputting complete events.

              Should the file or the last checkpointed event not be found, one of a number of errors
              will result and ausearch will terminate. See **EXIT STATUS **for detail.


       **--eoe-timeout _**seconds_
              Set  the  end of event parsing timeout. See **end_of_event_timeout **in [_auditd.conf(5)](https://www.chedong.com/phpMan.php/man/auditd.conf/5/markdown)_ for
              details. Note that setting this value will override  any  configured  value  found  in
              /etc/auditd/auditd.conf.

### -e, 
              Search for an event based on the given syscall _exit_ _code_ _or_ _errno_.

       **--escape _**option_
              This  option determines if the output is escaped to make the content safer for certain
              uses. The options are _raw_ , _tty_ , _shell_ , and  _shell_quote_.  Each  mode  includes  the
              characters of the preceding mode and escapes more characters. That is to say _shell_ in‐
              cludes all characters escaped by _tty_ and adds more. _tty_ is the default.

### --extra-keys
              When  the _format_ mode is _csv_, this option will add a final column with key information
              if its exists for the event. This would only occur on SYSCALL records which  were  the
              result of triggering an audit rule that defines a key.

### --extra-labels
              When the _format_ mode is _csv_, this option will add columns of information about subject
              and object labels when they exist.

### --extra-obj2
              When  the _format_ mode is _csv_, this option will add columns of information about a sec‐
              ond object when it exists. It's rare that a second object is part of  a  record.  Some
              examples  are  when  a  file  is  renamed from one name to another or when a device is
              mounted to a path.

### --extra-time
              When the _format_ mode is _csv_, this option will add columns of information about  broken
              down time to make subsetting easier.

### -f --file _
              Search  for an event based on the given _filename_. The argument will match normal files
              as well as af_unix sockets.

       **--format _**option_
              Events that match the search criteria are formatted using this option.  The  supported
              formats are: raw, default, interpret, csv, and text. The _raw_ option is described under
              the  _--raw_  command line option. The _default_ option is what you get when no formatting
              options are passed. It includes one line as a visual  separator  which  indicates  the
              time stamp and then the records of the event follow. The _interpret_ option is explained
              under  the _-i_ command line option. The _csv_ option outputs the results of the search as
              a normalized event in comma separated value (CSV) format suitable for import into ana‐
              lytical programs. The _text_ option turns the event into an  English  sentence  that  is
              easier  to  understand  than other options, but it comes at the expense of loss of de‐
              tail. In most cases this is perfectly fine since the original event still retains  all
              the original information.

### -ga --gid-all _
              Search  for  an  event  with  either effective group ID or group ID matching the given
              _group_ _ID_.

### -ge --gid-effective _
              Search for an event with the given _effective_ _group_ _ID_ or group name.

### -gi --gid _
              Search for an event with the given _group_ _ID_ or group name.

### -h --help
              Help

### -hn --host _
              Search for an event with the given _host_ _name_. The hostname can be either  a  hostname,
              fully qualified domain name, or numeric network address. No attempt is made to resolve
              numeric  addresses to domain names or aliases. This search typically correlates to the
              addr or host field of audit events. Also see the --node  command  which  searches  the
              node field.

### -i --interpret
              Interpret  numeric  entities into text. For example, uid is converted to account name.
              If the audit logs are unenriched, the conversion is done using the  current  resources
              of  the  machine  where  the search is being run. If you have renamed the accounts, or
              don't have the same accounts on your machine, you could get misleading results. If the
              logs are enriched, it uses the supplemental data to do the conversion. This allows ac‐
              curate log reporting even when run on a different machine than the original logs  came
              from.

### -if --input _
              Use the given _file_ or _directory_ instead of the logs. This is to aid analysis where the
              logs  have  been  moved  to  another machine or only part of a log was saved. The path
              length is limited to 4064 bytes.

### --input-logs
              Use the log file location from auditd.conf as input for searching. This is  needed  if
              you are using ausearch from a cron job.

### --just-one
              Stop after emitting the first event that matches the search criteria.

### -k --key _
              Search for an event based on the given _key_ _string_.

### -l --line-buffered
              Flush output on every line. Most useful when stdout is connected to a pipe and the de‐
              fault block buffering strategy is undesirable. May impose a performance penalty.

### -m --message _
              Search  for an event matching the given _message_ _type_. (Message types are also known as
              record types.) You may also enter a _comma_ _separated_ _list_ _of_ _message_ _types_ or  multiple
              individual  message  types  each  with its own _-m_ option. There is an **ALL **message type
              that doesn't exist in the actual logs. It allows you to get all messages in  the  sys‐
              tem. The list of valid messages types is long. The program will display the list when‐
              ever  no  message  type  is passed with this parameter. The message type can be either
              text or numeric. If you enter a list, there can be only commas and no spaces  separat‐
              ing the list.

### -n --node
              Search for events originating from a specific machine. Multiple nodes are allowed, and
              if  any  nodes  match,  the event is matched. This search uses the node field in audit
              events. Also see the --host command which search for events related to  host  informa‐
              tion in the audit trail.

### -o --object _
              Search for event with _tcontext_ (object) matching the string.

### -p --pid _
              Search for an event matching the given _process_ _ID_.

### -pp --ppid _
              Search for an event matching the given _parent_ _process_ _ID_.

### -r --raw
              Output is completely unformatted. This is useful for extracting records to a file that
              can still be interpreted by audit tools or when piping to other audit tools.

### -sc --syscall _
              Search  for  an  event  matching  the  given  _syscall_. You may either give the numeric
              syscall value or the syscall name. If you give the  syscall  name,  it  will  use  the
              syscall table for the machine that you are using.

### -se --context _
              Search  for  events with either _scontext_/subject or _tcontext_/object matching the given
              string.

       **--session _**Login-Session-ID_
              Search for events matching the given Login Session ID. This process attribute  is  set
              when a user logs in and can tie any process to a particular user login.

### -su --subject _
              Search for event with _scontext_ (subject) matching the string.

### -sv --success _
              Search for an event matching the given _success_ _value_. Legal values are **yes **and **no**.

### -te --end 
              Search  for  events with time stamps equal to or before the given end time. The format
              of end time depends on your locale. You can check the format of your locale by running
              **date '+%x'.  **If the date is omitted, **today **is assumed. If the time is omitted, **now  **is
              assumed.  Use 24 hour clock time rather than AM or PM to specify time. An example date
              using the en_US.utf8 locale is 09/03/2009. An example of time is  18:00:00.  The  date
              format accepted is influenced by the LC_TIME environmental variable.

              You  may also use the word: **now**, **recent**, **this-hour**, **boot**, **today**, **yesterday**, **this-week**,
              **week-ago**, **this-month**, or **this-year**. **Now **means starting now. **Recent **is 10 minutes  ago.
              **Boot **means the time of day to the second when the system last booted. **Today **means now.
              **Yesterday **is 1 second after midnight the previous day. **This-week **means starting 1 sec‐
              ond  after  midnight  on  day 0 of the week determined by your locale (see **localtime**).
              **Week-ago **means 1 second after midnight exactly 7 days ago. **This-month **means  1  second
              after  midnight  on day 1 of the month. **This-year **means the 1 second after midnight on
              the first day of the first month.

### -ts --start 
              Search for events with time stamps equal to or after the given start time. The  format
              of  start time depends on your locale. You can check the format of your locale by run‐
              ning **date '+%x'.  **If the date is omitted, **today **is assumed. If the  time  is  omitted,
              **midnight  **is  assumed. Use 24 hour clock time rather than AM or PM to specify time. An
              example date using the  en_US.utf8  locale  is  09/03/2009.  An  example  of  time  is
              18:00:00.  The  date  format accepted is influenced by the LC_TIME environmental vari‐
              able.

              You may also use the word: **now**, **recent**, **this-hour**, **boot**, **today**, **yesterday**,  **this-week**,
              **week-ago**, **this-month**, **this-year**, or **checkpoint**. **Boot **means the time of day to the sec‐
              ond  when the system last booted. **Today **means starting at 1 second after midnight. **Re‐**
              **cent **is 10 minutes ago. **Yesterday  **is  1  second  after  midnight  the  previous  day.
              **This-week  **means  starting  1 second after midnight on day 0 of the week determined by
              your locale (see **localtime**). **Week-ago **means starting 1 second after midnight exactly 7
              days ago. **This-month **means 1 second after midnight on day 1 of  the  month.  **This-year**
              means the 1 second after midnight on the first day of the first month.

              **checkpoint  **means _ausearch_ will use the timestamp found within a valid checkpoint file
              ignoring the recorded inode, device, serial, node and event type also found  within  a
              checkpoint  file.  Essentially,  this  is  the recovery action should an invocation of
              _ausearch_ with a checkpoint option fail with an exit status of 10, 11 or 12.  It  could
              be used in a shell script something like:

                   ausearch --checkpoint /etc/audit/auditd_checkpoint.txt -i
                   _au_status=$?
                   if test ${_au_status} eq 10 -o ${_au_status} eq 11 -o ${_au_status} eq 12
                   then
                     ausearch --checkpoint /etc/audit/auditd_checkpoint.txt --start checkpoint -i
                   fi

### -tm --terminal _
              Search  for  an event matching the given _terminal_ value. Some daemons such as cron and
              atd use the daemon name for the terminal.

### -ua --uid-all _
              Search for an event with either user ID, effective user ID, or login  user  ID  (auid)
              matching the given _user_ _ID_.

### -ue --uid-effective _
              Search for an event with the given _effective_ _user_ _ID_.

### -ui --uid _
              Search for an event with the given _user_ _ID_.

### -ul --loginuid _
              Search  for  an  event with the given _login_ _user_ _ID_. All entry point programs that are
              PAMified need to be configured with pam_loginuid required for the session for  search‐
              ing on loginuid (auid) to be accurate.

### -uu --uuid _
              Search for an event with the given _guest_ _UUID_.

### -v --version
              Print the version and exit

### -vm --vm-name _
              Search for an event with the given _guest_ _name_.

### -w --word
              String  based  matches  must  match  the whole word. This category of matches include:
              filename, hostname, terminal, keys, and SE Linux context.

### -x --executable _
              Search for an event matching the given _executable_ name.


## EXIT STATUS
       0    if OK,

       1    if nothing found, or argument errors or minor file access/read errors,

       10   invalid checkpoint data found in checkpoint file,

       11   checkpoint processing error

       12   checkpoint event not found in matching log file

## NOTE
       The boot time option is a convenience function and has limitations. The time it calculates is
       based on time now minus /proc/uptime. If after boot the system clock has been adjusted,  per‐
       haps by ntp, then the calculation may be wrong. In that case you'll need to fully specify the
       time. You can check the time it would use by running:

       date -d "`cut -f1 -d. /proc/uptime` seconds ago"


## EXAMPLES
       Search for a specific user:
       # ausearch --start today --loginuid john -i

       Check the SELinux log for any denials today
       # ausearch --start today -m avc -i

       Output logs in text format
       # ausearch --start today --format text

       Output TTY events interpreted and shell escaped
       # ausearch --start today -m TTY -i --escape shell_quote


## SEE ALSO
       [**auditd**(8)](https://www.chedong.com/phpMan.php/man/auditd/8/markdown), [**auditd.conf**(5)](https://www.chedong.com/phpMan.php/man/auditd.conf/5/markdown), [**aureport**(8)](https://www.chedong.com/phpMan.php/man/aureport/8/markdown), [**pam_loginuid**(8)](https://www.chedong.com/phpMan.php/man/pamloginuid/8/markdown).

Red Hat                                       July 2023                                  [_AUSEARCH_(8)](https://www.chedong.com/phpMan.php/man/AUSEARCH/8/markdown)
