All of lore.kernel.org
 help / color / mirror / Atom feed
* dispatch err (pipe full) event lost - audit-1.0.16-4 (2.6.9-67.0.4.ELsmp)
@ 2009-11-12 16:40 Rachamadagu, Vasu
  2009-11-13 14:06 ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Rachamadagu, Vasu @ 2009-11-12 16:40 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1194 bytes --]

Hi,

I could see following event logged continuously on messages log. I am
using audit-1.0.16 version with SnareLinux-1.5.0-1 version.

auditd[10959]: dispatch err (pipe full) event lost
auditd[10959]: dispatch error reporting limit reached - ending report
notification.
auditd[10959]: dispatch err (pipe full) event lost

--> /etc/audit.rules has only following line

-b 256

--> /etc/auditd.conf has following contents

log_file = /var/log/audit/audit.log
log_format = NOLOG
priority_boost = 3
flush = INCREMENTAL
freq = 20
num_logs = 4
#dispatcher = /sbin/audispd
#disp_qos = lossy
max_log_file = 5
max_log_file_action = ROTATE
space_left = 75
space_left_action = SYSLOG
action_mail_acct = root
admin_space_left = 50
admin_space_left_action = SUSPEND
disk_full_action = SUSPEND
disk_error_action = SUSPEND
dispatcher = /usr/sbin/SnareDispatchHelper

--> /etc/snare.conf

Normal remote log collection server IP and other details.

Above setup working from last couple of months without any errors but
all of sudden I could see above specified errors from last couple of
days. Is there any bug in audit version or snare version?

Regards,
Vasu



[-- Attachment #1.2: Type: text/html, Size: 5959 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread
[parent not found: <4A90605B9345DD489B4512A35AEB3A2804BB266A@nedexmb3.staplesams.com>]

end of thread, other threads:[~2009-11-13 14:39 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-11-12 16:40 dispatch err (pipe full) event lost - audit-1.0.16-4 (2.6.9-67.0.4.ELsmp) Rachamadagu, Vasu
2009-11-13 14:06 ` Steve Grubb
     [not found] <4A90605B9345DD489B4512A35AEB3A2804BB266A@nedexmb3.staplesams.com>
2009-11-13 14:39 ` dispatch err (pipe full) event lost - audit-1.0.16-4(2.6.9-67.0.4.ELsmp) Rachamadagu, Vasu

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.