Linux Auditd Log Parser
Paste raw Linux auditd records, ausearch -i output or an auditctl rule listing to get grouped events with actor, command, file and outcome fields, an explainable risk score, MITRE ATT&CK mapping and ready-to-paste investigation notes — entirely in your browser.
Auditd log input
Paste raw
/var/log/audit/audit.log lines, ausearch -i output, shipper JSON-lines, or an auditctl -l rule listing. Everything is parsed in your browser — nothing is uploaded.Examples:
Paste auditd records, or load an example, to see the normalized summary, risk score and ATT&CK mapping.