From: Matthew Booth <mbooth@redhat.com>
To: Steve Grubb <sgrubb@redhat.com>
Cc: linux-audit@redhat.com
Subject: Re: Auditd hangs hard
Date: Tue, 12 Jun 2007 17:54:30 +0100 [thread overview]
Message-ID: <1181667270.26075.12.camel@localhost.localdomain> (raw)
In-Reply-To: <200706121245.45399.sgrubb@redhat.com>
[-- Attachment #1.1: Type: text/plain, Size: 1324 bytes --]
On Tue, 2007-06-12 at 12:45 -0400, Steve Grubb wrote:
> It depends on how you have the configuration set. If you set disp_qos to
> lossy, then it should have discarded packets sent to the dispatcher. The only
> thing that it would be waiting on at that point is disk writing which has
> several tunables, too. If the dispatcher was the limiting factor, you may
> have to make it multi-threaded with one thread assigned to drain the auditd
> interface and write it to a fifo where another thread writes to syslog. This
> would allow the audit system to make better use of its time slice.
dispatcher qos set to lossy. All writing to disk disabled. Limiting
factor appeared to have been auditd not being scheduled often enough, so
the performance factor appears to be the behaviour of the kernel when
it's buffers are full.
> > If it's configured to drop messages rather than kill the system,
> > it could probably disable auditing entirely when the kernel buffer is
> > full, and only re-enable it when there's enough space.
>
> How big was the kernel buffer when you had problems? (Its adjustable.)
32k
Matt
--
Matthew Booth, RHCA, RHCSS
Red Hat, Global Professional Services
M: +44 (0)7977 267231
GPG ID: D33C3490
GPG FPR: 3733 612D 2D05 5458 8A8A 1600 3441 EA19 D33C 3490
[-- Attachment #1.2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
prev parent reply other threads:[~2007-06-12 16:54 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-06-08 14:32 Auditd hangs hard Matthew Booth
2007-06-09 11:59 ` Steve Grubb
2007-06-12 8:50 ` Matthew Booth
2007-06-12 16:45 ` Steve Grubb
2007-06-12 16:54 ` Matthew Booth [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1181667270.26075.12.camel@localhost.localdomain \
--to=mbooth@redhat.com \
--cc=linux-audit@redhat.com \
--cc=sgrubb@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox