sealert: add page (#18456)

Co-authored-by: Dylan <145150333+dmmqz@users.noreply.github.com>
This commit is contained in:
Pranav Lawate
2025-10-08 06:16:44 +03:00
committed by GitHub
co-authored by Dylan
parent f0f76c4eac
commit a1052a529d
+22
View File
@@ -0,0 +1,22 @@
# sealert
> Analyze and explain SELinux AVC denial messages.
> Part of the `setroubleshoot-server` package.
> See also: `audit2why`, `ausearch`, `audit2allow`.
> More information: <https://manned.org/sealert>.
- Analyze all recent SELinux denials:
`sudo sealert {{[-a|--analyze]}} {{/var/log/audit/audit.log}}`
- Analyze a specific alert ID from system logs:
`sudo sealert {{[-l|--lookupid]}} {{alert_id}}`
- Display a summary of recent SELinux alerts:
`sudo sealert {{[-b|--browser]}}`
- Monitor audit log in real-time for new alerts:
`sudo tail {{[-f|--follow]}} {{/var/log/audit/audit.log}} | sealert {{[-l|--lookupid]}} -`