Detection of external USB device on a server running Linux
1. Task statement.
As part of meeting regulatory requirements, it was necessary to prepare an evidentiary base for auditors regarding monitoring events of external USB devices being connected to a server running Linux.
This "Monitoring Note" presents example events obtained from practical testing of current releases of Linux operating systems: CentOS Stream 9 and Ubuntu Server 26.04 LTS.
2. Test results.
2.1. Operating system CentOS Stream 9.
When the device was connected, the following sequence was observed:
Aug 24 13:36:25 centos9 kernel: usb 2-1: new SuperSpeed USB device number 7 using xhci_hcd
Aug 24 13:36:25 centos9 kernel: usb 2-1: New USB device found, idVendor=174c, idProduct=55aa, bcdDevice= 0.01
Aug 24 13:36:25 centos9 kernel: usb 2-1: New USB device strings: Mfr=2, Product=3, SerialNumber=1
Aug 24 13:36:25 centos9 kernel: usb 2-1: Product: Silicon-Power
Aug 24 13:36:25 centos9 kernel: usb 2-1: Manufacturer: PHD 3.0
Aug 24 13:36:25 centos9 kernel: usb 2-1: SerialNumber: 20021560216000000018
Aug 24 13:36:25 centos9 kernel: usb 2-1: USB controller 0000:00:0c.0 does not support streams, which are required by the UAS driver.
Aug 24 13:36:25 centos9 kernel: usb 2-1: Please try an other USB controller if you wish to use UAS.Later, a disconnection was observed:
Aug 24 13:45:41 centos9 kernel: usb 2-1: USB disconnect, device number 7In this fragment a single cycle is observed: detection of the device in 13:36:25 and its disconnection in 13:45:41. The number 7 is present both at detection and at disconnection.
2.2. Operating system Ubuntu Server 26.04 LTS.
When the device was connected, the following sequence was observed:
2026-08-24T14:17:49.140130+05:00 ubuntu-web kernel: usb 2-1: new SuperSpeed USB device number 2 using xhci_hcd
2026-08-24T14:17:49.140152+05:00 ubuntu-web kernel: usb 2-1: New USB device found, idVendor=174c, idProduct=55aa, bcdDevice= 0.01
2026-08-24T14:17:49.140153+05:00 ubuntu-web kernel: usb 2-1: New USB device strings: Mfr=2, Product=3, SerialNumber=1
2026-08-24T14:17:49.140153+05:00 ubuntu-web kernel: usb 2-1: Product: Silicon-Power
2026-08-24T14:17:49.140154+05:00 ubuntu-web kernel: usb 2-1: Manufacturer: PHD 3.0
2026-08-24T14:17:49.140154+05:00 ubuntu-web kernel: usb 2-1: SerialNumber: 20021560216000000018
2026-08-24T14:17:49.140245+05:00 ubuntu-web kernel: usb 2-1: USB controller 0000:00:0c.0 does not support streams, which are required by the UAS driver.
2026-08-24T14:17:49.140246+05:00 ubuntu-web kernel: usb 2-1: Please try an other USB controller if you wish to use UAS.Device disconnection:
2026-08-24T14:21:59.841505+05:00 ubuntu-web kernel: usb 2-1: USB disconnect, device number 2Here a single cycle of detection and disconnection is also observed. The idVendor, idProductstring characteristics and serial number match. The number 2 is present both at detection and at disconnection.
3. Conclusion.
A normal connection and disconnection of a USB device is detected by the Linux kernel and is accompanied by notifications processed by udev. You cannot assume that it will automatically create records USER_DEVICE, DEV_ALLOC or DEV_DEALLOC in Linux Audit. Such records depend on the presence and configuration of components that generate them. An example for USER_DEVICE is USBGuard with Linux Audit integration enabled.