The preceding directories are the default Docker installation directories. If a separate partition is created for Docker, the paths may change. For details about how to enable the audit function, see Enabling Docker Audit.
By default, the audit function is disabled on the host. You can add an audit rule in either of the following ways:
To enable the audit mechanism, install the auditd software first. You can run the apt install -y auditd command to install the software in the Ubuntu system.
-w file_path -k docker
Parameter |
Description |
|---|---|
-w |
Path of the file to be filtered |
file_path |
Path of the file for which the audit rule is enabled. Examples:
|
-k |
String filtering based on specified keywords |
If the /etc/audit/audit.rules file contains This file is automatically generated from /etc/audit/rules.d, the modification to the file is invalid. In this case, you need to modify the /etc/audit/rules.d/audit.rules file for the modification to take effect. For example, in the Ubuntu system, you need to modify the /etc/audit/rules.d/audit.rules file.
Note: If the audit function is enabled, a large number of log files will be generated. You need to dump the log files periodically, so partition the audit function separately.
service auditd restart