audit2allow Command Examples

Create an SELinux local policy module to allow rules based on denied operations found in logs. Note: Use audit2allow with caution—always review the generated policy before applying it, as it may allow excessive access. More information: https://manned.org/audit2allow.

sudo audit2allow --all -M {{local_policy_name}}

sudo grep {{apache2}} /var/log/audit/audit.log | sudo audit2allow -M {{local_policy_name}}

vim {{local_policy_name}}.te

sudo semodule -i {{local_policy_name}}.pp