Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7039: In Direct Audit, with command auditing enabled, two sessions were logged instead of one.

Auditing and Monitoring Service ,  

9 April,21 at 05:23 PM

Applies to:

DirectAudit 3.3.0 & 3.3.1 ( Centrify Server Suite 2016 & 2016.1)


Problem:

In Direct Audit  with command auditing enabled for both su and dzdo, when a user run "dzdo su - root", two sessions were logged instead of one.


Cause:

In Suite 2016 and 2016.1 for command auditing, a flaw in the logic caused Direct Audit  to send the child sessions audited data to the collector. 


Workaround:

The issue can be work around by adding a new parameter to the file /etc/centrifyda/centrifyda.conf like this:


dash.parent.skiplist: sapstartsrv gdm-binary gdm-session-wor kdm sdt_shell dzdo sudo sudo.daudit

Customer can also use the group policy to set up the same parameter.

"Centrify DirectAudit Settings" -> "DirectAudit Shell Settings" -> "Set parent process skip list"


Resolution:

This issue was fixed in the 2017 (5.4.0) Suite release.