The fields in the SIR report have the following meanings:
Host
The machine protected by AppArmor for which the security events are reported.
Date
The date during which security events occurred.
Program
The name of the executing process.
Profile
The absolute name of the security profile that is applied to the process.
PID
A number that uniquely identifies one specific process or running program (this
number is valid only during the lifetime of that process).
Severity
Severity levels of events are reported from the severity database. The severity
database defines the importance of potential security events and numbers them 1
through 10, 10 being the most severe security incident. The severity levels are de-
Managing Profiled Applications
99