All of lore.kernel.org
 help / color / mirror / Atom feed
* Filter for audit.log
@ 2009-12-21 15:46 corbin
  2009-12-22 19:13 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: corbin @ 2009-12-21 15:46 UTC (permalink / raw)
  To: linux-audit

Hello, we have installed Splunk in order to monitor the audit.log files of
several systems.  However, our audit.log files are turning over quicker
than usual since Splunk seems to span our audit.log file with entries.

Is there a way to get audit.log to filter messages from Splunk in RHEL 5
server systems?

Thanks in advance!
Starr

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-12-22 19:13 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-12-21 15:46 Filter for audit.log corbin
2009-12-22 19:13 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.