Severity
Select the lowest severity level for security events to include in the report.
The selected severity level and above are included in the reports.
Detail
A source to which the profile has denied access. This includes capabilities
and files. You can use this field to report the resources to which profiles
prevent access.
Access Type
The access type describes what is actually happening with the security event.
The options are
PERMITTING
,
REJECTING
, or
AUDITING
.
Mode
The mode is the permission that the profile grants to the program or process
to which it is applied. The options are
r
(read),
w
(write),
l
(link), and
x
(execute).
Export Type
Enables you to export a CSV (comma separated values) or HTML file. The
CSV file separates pieces of data in the log entries with commas using a
standard data format for importing into table-oriented applications. Enter a
path for your exported report by typing in the full path in the field provided.
Location to Store Log
Enables you to change the location that the exported report is stored. The
default location is
/var/log/apparmor/reports-exported
. When
you change this location, select Accept. Select Browse to browse the file
system.
5
To see the report, filtered as desired, select Next. One of the three reports displays.
Refer the following sections for detailed information about each type of report.
• For the application audit report, refer to
Section “Application Audit Report”
(page 97).
• For the security incident report, refer to
Section “Security Incident Report”
(page 98).
Managing Profiled Applications
103