专属域名
文档搜索
轩辕助手
Run助手
邀请有礼
返回顶部
快速返回页面顶部
收起
收起工具栏
轩辕镜像 官方专业版
轩辕镜像 官方专业版轩辕镜像 官方专业版官方专业版
首页个人中心搜索镜像

交易
充值流量我的订单
工具
提交工单镜像收录一键安装
Npm 源Pip 源Homebrew 源
帮助
常见问题
其他
关于我们网站地图

官方QQ群: 1072982923

teacherspayteachers/linux-audit-exporter Docker 镜像 - 轩辕镜像

linux-audit-exporter
teacherspayteachers/linux-audit-exporter
Export Linux audit metrics in Prometheus format
0 次下载
🚀 稳定镜像源 = 更少宕机 + 更低运维成本
镜像简介版本下载
🚀 稳定镜像源 = 更少宕机 + 更低运维成本

linux-audit-exporter

A Prometheus exporter for Linux Audit status.

Project Status

This project is:

  • In ALPHA state
  • Is maintained by Teachers Pay Teachers
  • Is used in production by Teachers Pay Teachers
Versioning

While this project is in ALPHA status, breaking changes may occur between minor versions, and will be announced in CHANGELOG.md and in the GitHub release notes.

The API surface area includes:

  • Runtime dependencies
  • The Helm chart values
  • The CLI flags and environment variables
  • The exported Prometheus metric names and labels

Requirements

Golang 1.14+ is required to build the project.

Will run on any system that can run Go binaries, but will only export Linux Audit status when run from a Linux host. When run from a non-Linux host, it will export zero-ed metrics.

Additionally, requires:

  • Root (UID 0) user to run binary
  • Audit read privilege (CAP_AUDIT_READ)
  • --host=pid in Docker, hostPID: true in Kubernetes

Why

The Linux audit system can be configured to log security-relevant events such as syscalls, and processed by auditd or commercial alternatives.

On high-throughput systems it may generate audit records at a faster pace than auditd (or equivalent) can consume. Depending on how Linux audit is configured, this can result in:

  • Lost audit events
  • Backlog processing delays
  • Out-of-memory

The linux-audit-exporter surfaces metrics meant to help operators monitor the status of the Linux audit system, and avoid these outcomes.

Build

Go binary
$ go build .
Docker image
$ docker build .

Usage

Help
$ linux-audit-exporter -h
Export Linux audit status as Prometheus metrics

Usage:
  linux-audit-exporter [flags]

Flags:
      --health-path string      health path (default "/healthz")
  -h, --help                    help for linux-audit-exporter
      --listen-address string   listen address (default "0.0.0.0:9090")
      --metrics-path string     metrics path (default "/metrics")
Run

Run binary directly:

$ linux-audit-exporter

Or, use Docker image:

$ docker run -p 9090:9090 --privileged TeachersPayTeachers/linux-audit-exporter
Get metrics
$ curl localhost:9090/metrics | grep linux_audit

Deploy

Docker

Docker images are published here.

$ docker run --privileged teacherspayteachers/linux-audit-exporter:latest
Helm

A Helm chart is available, which deploys linux-audit-exporter as a DaemonSet.

$ helm repo add tpt [***]
$ helm install linux-audit-exporter tpt/linux-audit-exporter

The Helm chart code is located here.

Metrics

When run from a Linux host with required privileges, will export Linux Audit status as Prometheus metrics. Here is a sample:

# HELP linux_audit_backlog Number of event records currently queued waiting for auditd to read them.
# TYPE linux_audit_backlog gauge
linux_audit_backlog 0
# HELP linux_audit_backlog_limit Number of outstanding audit buffers allowed.
# TYPE linux_audit_backlog_limit gauge
linux_audit_backlog_limit 5000
# HELP linux_audit_backlog_wait_time Time kernel waits when backlog limit is reached.
# TYPE linux_audit_backlog_wait_time gauge
linux_audit_backlog_wait_time ***
# HELP linux_audit_backlog_wait_time_actual Total time spent by kernel waiting to queue audit events on backlog.
# TYPE linux_audit_backlog_wait_time_actual gauge
linux_audit_backlog_wait_time_actual 10
# HELP linux_audit_enabled Enabled flag. 0 = disabled. 1 = enabled. 2 = immutable. -1 = unknown.
# TYPE linux_audit_enabled gauge
linux_audit_enabled 1
# HELP linux_audit_failure Number of critical errors, such as transmission errors, backlog limit exceeded, etc.
# TYPE linux_audit_failure gauge
linux_audit_failure 0
# HELP linux_audit_lost Number of event records that have been discarded due to kernel audit queue overflowing.
# TYPE linux_audit_lost gauge
linux_audit_lost 0
# HELP linux_audit_rate_limit Limit of messages per second. A value of zero means no rate limit is applied.
# TYPE linux_audit_rate_limit gauge
linux_audit_rate_limit ***

Alternatives

printk and dmesg

The Linux audit system can be configured to log failures and lost events with printk, which can usually be read with dmesg.

StatsD plugin

There is an (experimental, at time of this writing) user-space StatsD plugin.

Contributing

Contributions are very welcome!

Please see CONTRIBUTING.md for information on how to contribute changes to this project.

Release

When new commits are merged to the main branch, an internal process will automatically create a new GitHub release, Docker image, and Helm chart if there are any new fix: or feat: commits.

Note to Teachers Pay Teachers employees: see this internal wiki for information about this process.

Continuous Integration

New commits or pull requests to this project are automatically built, linted and tested by GitHub Actions. See the ./github/workflows/ci.yaml file for the configuration of CI actions.

License

MIT

查看更多 linux-audit-exporter 相关镜像 →
rockylinux/rockylinux logo
rockylinux/rockylinux
社区支持的Linux发行版,基于Red Hat提供的RHEL源代码构建,功能兼容RHEL,移除上游厂商品牌与图标,免费可再分发,每个版本提供长达10年维护。
991M+ pulls
上次更新:未知
archlinux/archlinux logo
archlinux/archlinux
Arch Linux提供符合OCI标准的容器镜像,通过多个仓库分发,包括DockerHub官方库(每周更新)及DockerHub、quay.io的archlinux仓库(每日更新),适用于构建和运行容器化的Arch Linux环境。
241M+ pulls
上次更新:未知
bitnami/node-exporter logo
bitnami/node-exporter
Bitnami安全版node-exporter镜像,用于节点监控,收集主机系统及硬件指标。
2550M+ pulls
上次更新:未知
bitnami/redis-exporter logo
bitnami/redis-exporter
Bitnami安全镜像,集成redis-exporter工具,用于安全导出Redis监控指标。
16100M+ pulls
上次更新:未知
bitnami/jmx-exporter logo
bitnami/jmx-exporter
Bitnami提供的安全镜像,用于运行jmx-exporter以导出JMX指标,适用于Java应用监控场景。
810M+ pulls
上次更新:未知
archlinux logo
archlinux
Arch Linux是一款简洁、轻量级的Linux发行版,以灵活性为核心目标,它采用滚动更新模式,强调极简设计与用户自主配置,允许用户从零开始构建符合个人需求的系统,凭借高效的包管理工具(如pacman)和活跃的社区支持,深受追求系统掌控权与定制化体验的技术用户青睐,在保持轻量的同时为用户提供高度自由的操作空间。
65410M+ pulls
上次更新:未知

轩辕镜像配置手册

探索更多轩辕镜像的使用方法,找到最适合您系统的配置方式

登录仓库拉取

通过 Docker 登录认证访问私有仓库

Linux

在 Linux 系统配置镜像服务

Windows/Mac

在 Docker Desktop 配置镜像

Docker Compose

Docker Compose 项目配置

K8s Containerd

Kubernetes 集群配置 Containerd

K3s

K3s 轻量级 Kubernetes 镜像加速

Dev Containers

VS Code Dev Containers 配置

MacOS OrbStack

MacOS OrbStack 容器配置

宝塔面板

在宝塔面板一键配置镜像

群晖

Synology 群晖 NAS 配置

飞牛

飞牛 fnOS 系统配置镜像

极空间

极空间 NAS 系统配置服务

爱快路由

爱快 iKuai 路由系统配置

绿联

绿联 NAS 系统配置镜像

威联通

QNAP 威联通 NAS 配置

Podman

Podman 容器引擎配置

Singularity/Apptainer

HPC 科学计算容器配置

其他仓库配置

ghcr、Quay、nvcr 等镜像仓库

专属域名拉取

无需登录使用专属域名

需要其他帮助?请查看我们的 常见问题Docker 镜像访问常见问题解答 或 提交工单

镜像拉取常见问题

轩辕镜像免费版与专业版有什么区别?

免费版仅支持 Docker Hub 访问,不承诺可用性和速度;专业版支持更多镜像源,保证可用性和稳定速度,提供优先客服响应。

轩辕镜像支持哪些镜像仓库?

专业版支持 docker.io、gcr.io、ghcr.io、registry.k8s.io、nvcr.io、quay.io、mcr.microsoft.com、docker.elastic.co 等;免费版仅支持 docker.io。

流量耗尽错误提示

当返回 402 Payment Required 错误时,表示流量已耗尽,需要充值流量包以恢复服务。

410 错误问题

通常由 Docker 版本过低导致,需要升级到 20.x 或更高版本以支持 V2 协议。

manifest unknown 错误

先检查 Docker 版本,版本过低则升级;版本正常则验证镜像信息是否正确。

镜像拉取成功后,如何去掉轩辕镜像域名前缀?

使用 docker tag 命令为镜像打上新标签,去掉域名前缀,使镜像名称更简洁。

查看全部问题→

用户好评

来自真实用户的反馈,见证轩辕镜像的优质服务

用户头像

oldzhang

运维工程师

Linux服务器

5

"Docker访问体验非常流畅,大镜像也能快速完成下载。"

轩辕镜像
镜像详情
...
teacherspayteachers/linux-audit-exporter
官方博客Docker 镜像使用技巧与技术博客
热门镜像查看热门 Docker 镜像推荐
一键安装一键安装 Docker 并配置镜像源
咨询镜像拉取问题请 提交工单,官方技术交流群:1072982923
轩辕镜像面向开发者与科研用户,提供开源镜像的搜索和访问支持。所有镜像均来源于原始仓库,本站不存储、不修改、不传播任何镜像内容。
咨询镜像拉取问题请提交工单,官方技术交流群:
轩辕镜像面向开发者与科研用户,提供开源镜像的搜索和访问支持。所有镜像均来源于原始仓库,本站不存储、不修改、不传播任何镜像内容。
官方邮箱:点击复制邮箱
©2024-2026 源码跳动
官方邮箱:点击复制邮箱Copyright © 2024-2026 杭州源码跳动科技有限公司. All rights reserved.