Information
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Security_Guide/chap-system_auditing.html
2.https://docs.docker.com/engine/reference/commandline/daemon/#daemon-configuration-file
Solution
Add a rule for /etc/docker/daemon.json file.For example,Add the line as below in /etc/audit/audit.rules file--w /etc/docker/daemon.json -k dockerThen, restart the audit daemon. For example,service auditd restart
Impact-Auditing generates quite big log files. Ensure to rotate and archive them periodically. Also,
create a separate partition of audit to avoid filling root file system.Default Value-By default, Docker related files and directories are not audited. The file
/etc/docker/daemon.json may not be available on the system. In that case, this
recommendation is not applicable.