audit.log flooded by messages with commvault

Solution Verified - Updated -

Issue

  • audit.log is flooded with AVC messags concerning ip and commvault like below:

    type=PROCTITLE msg=audit(06/29/2021 14:10:09.454:1346022) : proctitle=ip -f inet -o a 
    type=PATH msg=audit(06/29/2021 14:10:09.454:1346022) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=281156 dev=fd:04 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:ld_so_t:s0 objtype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
    type=PATH msg=audit(06/29/2021 14:10:09.454:1346022) : item=0 name=/usr/sbin/ip inode=289352 dev=fd:04 mode=file,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_exec_t:s0 objtype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
    type=CWD msg=audit(06/29/2021 14:10:09.454:1346022) :  cwd=/opt/commvault 
    type=EXECVE msg=audit(06/29/2021 14:10:09.454:1346022) : argc=5 a0=ip a1=-f a2=inet a3=-o a4=a 
    type=SYSCALL msg=audit(06/29/2021 14:10:09.454:1346022) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x11143e0 a1=0x111ab00 a2=0x1116f10 a3=0x7ffdbaecb8b0 items=2 ppid=12663 pid=12664 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ip exe=/usr/sbin/ip subj=system_u:system_r:ifconfig_t:s0 key=(null) 
    type=AVC msg=audit(06/29/2021 14:10:09.454:1346022) : avc:  denied  { read append } for  pid=12664 comm=ip path=/opt/log/commvault/Log_Files/fwd.log dev="dm-4" ino=148396 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:default_t:s0 tclass=file permissive=0 
    

Environment

  • RHEL
  • selinux

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content