Previous Topic: System Call Notification ActionNext Topic: System Call Status Action


System Call Operation Action

The System Call Operation action expresses information on system call operations. A system call is a request made by any program to the operating system for performing tasks. System calls provide the interface between a process and the operating system. When an event is recorded as part of normal system call functions, or if the event cannot be mapped to a more specific CEG action, consider mapping the event to this action.

Information

Level

Source - User Information

Secondary

Source - Host Information

Tertiary

Source - Object Information

Tertiary

Source - Process Information

Tertiary

Source - Group Information

Tertiary

Dest - User Information

Tertiary

Dest - Host Information

Primary

Dest - Object Information

Primary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

Result

event_result

event_severity

Success

S

2

Failure

F

3