Skip to content

The Linux agent only captures journald. #1956

@yllada

Description

@yllada

Acknowledgements

Describe the bug

The Linux agent only collects logs via journalctl -f -o json, missing critical security events that require auditd.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

The Linux agent should have comprehensive log collection.

Current Behavior

N/A

Reproduction Steps

  1. Install UTMStack agent on Debian/Ubuntu server
  2. Run any command: whoami, cat /etc/passwd, chattr +i file
  3. Check SIEM logs for the command → Not captured

Possible Solution

Add native auditd collector to the agent.

Additional Information/Context

No response

UTMStack Version

v11

Operating System and version

Ubuntu

Hypervisor and Version | Server Vendor and Model

n/a

Browser and version

na

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Status

👀 In review

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions