audit2allow
Generate SELinux policy allow rules from audit logs. Part of the `policycoreutils-python-utils` package. See also: `audit2why`, `ausearch`, `semodule`.
More info →Options (8)
-a, --allbooleanGenerate allow rules from recent audit denials and display them
sudo audit2allow {{[-a|--all]}}-i, --inputbooleanGenerate allow rules from a specific audit log file
sudo audit2allow {{[-i|--input]}} {{path/to/audit.log}}-M, --modulebooleanGenerate a policy module from recent audit denials
sudo audit2allow {{[-a|--all]}} {{[-M|--module]}} {{module_name}}-e, --explainbooleanDisplay detailed information around generated messages
sudo audit2allow {{[-a|--all]}} {{[-e|--explain]}}-R, --referencebooleanUse installed macros to generate a reference policy
sudo audit2allow {{[-a|--all]}} {{[-R|--reference]}}-m, --messagebooleanGenerate allow rules for a specific service
sudo ausearch {{[-m|--message]}} avc {{[-c|--comm]}} {{service_name}} | audit2allow {{[-M|--module]}} {{policy_name}}-c, --commbooleanGenerate allow rules for a specific service
sudo ausearch {{[-m|--message]}} avc {{[-c|--comm]}} {{service_name}} | audit2allow {{[-M|--module]}} {{policy_name}}-v, --verbosebooleanEnable verbose output mode
sudo audit2allow {{[-a|--all]}} {{[-v|--verbose]}}Examples (8)
Generate allow rules from recent audit denials and display them
sudo audit2allow [-a|--all]Generate allow rules from a specific audit log file
sudo audit2allow [-i|--input] path/to/audit.logGenerate a policy module from recent audit denials
sudo audit2allow [-a|--all] [-M|--module] module_nameExplain why SELinux denials occurred (same as `audit2why`)
sudo audit2allow [-a|--all] --whyDisplay detailed information around generated messages
sudo audit2allow [-a|--all] [-e|--explain]Use installed macros to generate a reference policy
sudo audit2allow [-a|--all] [-R|--reference]Generate allow rules for a specific service
sudo ausearch [-m|--message] avc [-c|--comm] service_name | audit2allow [-M|--module] policy_nameEnable verbose output mode
sudo audit2allow [-a|--all] [-v|--verbose]