4 ms·
The audit framework is less flexible in what you can get events for. eBPF gives you basically unlimited options, though you have to implement it yourself. Addit
by openasocket 3y ago
The audit framework is less flexible in what you can get events for. eBPF gives you basically unlimited options, though you have to implement it yourself. Additionally the audit framework is wonky. There's the kernel side plus a userspace daemon that logs the audit data to disk. If you want to implement your own daemon to act as the audit agent, maybe to do something more sophisticated than just logging to disk, it gets complicated. There's very little documentation on how to implement such a custom daemon, you basically have to just copy what the existing agent does and hope you aren't subtly breaking things.