systemctl status auditd.service命令发现auditd.service(审计服务)异常,并提示:Condition check resulted in securityAuditing Service being skipped
1.使用命令查看内核是否已开启审计功能
grep "audit" /etc/default/grub
里面如果audit=0,则表示系统内核未开启审计功能。
2.编辑GRUB配置文件,将文件中audit=0改为audit=1
vim /etc/default/grub
3.查找GRUB配置
find /