Actually, with Linux in general, everything needs "some work" to be done. A"Linux box" is a very broad term and a Linux server can be based on one of many different distributions (or even be installed as LFS), can be configured in a gazillion different ways so while you could cover some typical cases (like RHEL9/default install/default rsyslog configuration), there is no way to cover "any Linux". Also remember that audit logs depend greatly (mostly, if not exclusively) on which audit rules you have defined in your system.
... View more