Linux Log File Tampering Detected

This rule detects attempts to tamper with critical Linux log files such as /var/log/auth.log, /var/log/syslog, and /var/log/audit/audit.log. It specifically looks for file deletion or modification events, or process creation events that involve commands like 'rm', 'shred', 'truncate', 'unlink', or 'dd' targeting these log files. Legitimate processes like 'logrotate', 'rsyslog', 'syslog-ng', 'auditd', 'systemd', and 'journald' are excluded to reduce false positives.