laurel 0.7.3

Transform Linux Audit logs for SIEM usage
Documentation
1
{"ID":"1634728455.294:53732","SYSCALL":{"arch":"0xc000003e","syscall":1,"success":"yes","exit":19577,"items":0,"ppid":3981294,"pid":3981295,"auid":4294967295,"uid":0,"gid":0,"euid":0,"suid":0,"fsuid":0,"egid":0,"sgid":0,"fsgid":0,"tty":"(none)","ses":4294967295,"comm":"apparmor_parser","exe":"/usr/sbin/apparmor_parser","subj":"unconfined","key":null,"ARCH":"x86_64","SYSCALL":"write","AUID":"unset","UID":"root","GID":"root","EUID":"root","SUID":"root","FSUID":"root","EGID":"root","SGID":"root","FSGID":"root","ARGV":["0x7","0x560174cd7790","0x4c79","0x0"]},"AVC":[{"apparmor":"STATUS","operation":"profile_replace","info":"same as current profile, skipping","profile":"unconfined","name":"snap-update-ns.amazon-ssm-agent","pid":3981295,"comm":"apparmor_parser"}]}