Enabling Docker Audit

Audit Content

Enabling Docker Audit

By default, the audit function is disabled on the host. You can add an audit rule in either of the following ways:

To enable the audit mechanism, install the auditd software first. You can run the apt install -y auditd command to install the software in the Ubuntu system.

  1. Add rules to the /etc/audit/audit.rules file. Each rule occupies a line. The rule format is as follows:

    -w file_path -k docker
    Table 1 Parameter description

    Parameter

    Description

    -w

    Path of the file to be filtered

    file_path

    Path of the file for which the audit rule is enabled. Examples:

    • If file_path is set to /usr/bin/docker, the host audits the Docker daemon.
    • If file_path is set to /etc/docker, the host audits Docker directories and key files.

    -k

    String filtering based on specified keywords

    If the /etc/audit/audit.rules file contains This file is automatically generated from /etc/audit/rules.d, the modification to the file is invalid. In this case, you need to modify the /etc/audit/rules.d/audit.rules file for the modification to take effect. For example, in the Ubuntu system, you need to modify the /etc/audit/rules.d/audit.rules file.

    Note: If the audit function is enabled, a large number of log files will be generated. You need to dump the log files periodically, so partition the audit function separately.

  2. After the configuration is complete, restart the log daemon process.

    service auditd restart