From mboxrd@z Thu Jan 1 00:00:00 1970 From: Klaus Heinrich Kiwi Subject: Re: audit 1.7.4 released Date: Tue, 27 May 2008 13:57:28 -0300 Message-ID: <1211907448.17805.1.camel@klausk.br.ibm.com> References: <200805191450.06153.sgrubb@redhat.com> <1211903431.6568.41.camel@homeserver> <200805271210.04007.sgrubb@redhat.com> <1211904978.6568.53.camel@homeserver> Mime-Version: 1.0 Content-Type: text/plain Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1211904978.6568.53.camel@homeserver> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: LC Bruzenak Cc: Linux Audit List-Id: linux-audit@redhat.com On Tue, 2008-05-27 at 11:16 -0500, LC Bruzenak wrote: > On Tue, 2008-05-27 at 12:10 -0400, Steve Grubb wrote: > ... > > > Once we aggregate these would be tough to separate. > > > > That is why we added the node field. :) You should probably enable it with > > the name_format option. > > I think I do have it: > > [root@hugo audit]# grep name_format /etc/audit/auditd.conf > name_format = hostname Isn't the audit dispatcher's role of adding the node name in the record? If so, only records going through the audispd would have this field. -K -- Klaus Heinrich Kiwi Security Development - IBM Linux Technology Center