Вот пример 3 событий:
1594639453.504:2913933860
sudo ausearch -a 2913933860 -i
----
type=PATH msg=audit(07/13/2020 11:24:13.504:2913933860) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=****** dev=**:** mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=PATH msg=audit(07/13/2020 11:24:13.504:2913933860) : item=0 name=/***/***/bin/python2.7 inode=****** dev=**:** mode=file,555 ouid=***** ogid=***** rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=EXECVE msg=audit(07/13/2020 11:24:13.504:2913933860) : argc=3 a0=/***/***/bin/python2.7 a1=/***/***/bin/***.py a2=execute
type=SYSCALL msg=audit(07/13/2020 11:24:13.504:2913933860) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x*** a1=0x*** a2=0x*** a3=0x*** items=2 ppid=13317 pid=38930 auid=*** uid=*** gid=*** euid=*** suid=*** fsuid=*** egid=*** sgid=*** fsgid=*** tty=(none) ses=124677 comm=python2.7 exe=/***/***/bin/python2.7 key=TEST
1594639453.596:2913933863
sudo ausearch -a 2913933863 -i
----
type=PATH msg=audit(07/13/2020 11:24:13.596:2913933863) : item=2 name=/lib64/ld-linux-x86-64.so.2 inode=****** dev=**:** mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=PATH msg=audit(07/13/2020 11:24:13.596:2913933863) : item=1 name=/bin/sh inode=****** dev=**:** mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=PATH msg=audit(07/13/2020 11:24:13.596:2913933863) : item=0 name=/sbin/ldconfig inode=****** dev=fd:0b mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=EXECVE msg=audit(07/13/2020 11:24:13.596:2913933863) : argc=3 a0=/bin/sh a1=/sbin/ldconfig a2=-p
type=SYSCALL msg=audit(07/13/2020 11:24:13.596:2913933863) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x*** a1=0x*** a2=0x*** a3=0x*** items=3 ppid=38930 pid=38935 auid=*** uid=*** gid=*** euid=*** suid=*** fsuid=*** egid=*** sgid=*** fsgid=*** tty=(none) ses=124677 comm=ldconfig exe=/bin/dash key=TEST
1594639453.676:2913933866
sudo ausearch -a 2913933866 -i
----
type=PATH msg=audit(07/13/2020 11:24:13.676:2913933866) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=****** dev=**:** mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=PATH msg=audit(07/13/2020 11:24:13.676:2913933866) : item=0 name=/bin/uname inode=****** dev=**:** mode=file,755 ouid=root ogid=root rdev=00:00 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0
type=EXECVE msg=audit(07/13/2020 11:24:13.676:2913933866) : argc=2 a0=uname a1=-p
type=SYSCALL msg=audit(07/13/2020 11:24:13.676:2913933866) : arch=x86_64 syscall=execve success=yes exit=0 a0=*** a1=0x*** a2=0x*** a3=0x1 items=2 ppid=38938 pid=38939 auid=*** uid=*** gid=*** euid=*** suid=*** fsuid=*** egid=*** sgid=*** fsgid=*** tty=(none) ses=124677 comm=uname exe=/bin/uname key=TEST