Audit logs in enriched format log events for containers resolve to wrong UID/GID
Issue
- In the container, there is a user A with uid 56789, and on the host there is a user B with same uid 56789. So in the event generated from container, user name B is resolved and writen in the log, which is not correct
- audit log shows wrong username executed commands
log_format = ENRICHED
breaks containerized user event auditing
Environment
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- auditd
- podman
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.