From mboxrd@z Thu Jan 1 00:00:00 1970 From: Kevin Boyce Subject: Re: Audit issues with Snare version 1.5 and RHEL 5.3 x86_64 Date: Mon, 27 Apr 2009 18:03:48 -0400 Message-ID: <1240869828.30727.346.camel@pc070168.northgrum.com> References: <005101c9c77d$42aec840$8200a8c0@referentia.com> Reply-To: kevin.boyce@ngc.com Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0566443364==" Return-path: Received: from mx3.redhat.com (mx3.redhat.com [172.16.48.32]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id n3RM4eXv023657 for ; Mon, 27 Apr 2009 18:04:40 -0400 Received: from xmrt0101.northgrum.com (xmrt0101.northgrum.com [208.20.220.55]) by mx3.redhat.com (8.13.8/8.13.8) with ESMTP id n3RM4NLd022821 for ; Mon, 27 Apr 2009 18:04:24 -0400 In-Reply-To: <005101c9c77d$42aec840$8200a8c0@referentia.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Dave Trepanier Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============0566443364== Content-Type: multipart/alternative; boundary="=-VFEF31YaS3Hv7iO0slol" --=-VFEF31YaS3Hv7iO0slol Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I think the auditd package that ships with 5.3 has a bug. Use one of the newer versions available from http://people.redhat.com/sgrubb/audit/index.html On Mon, 2009-04-27 at 11:15 -1000, Dave Trepanier wrote: > uditd audit.log files stops receiving log entries until the auditd > service is stopped and restarted. The logs entries re-start also > after I run audit =E2=80=93f. I have been thinking about updating auditd= , > currently release 7.7.7-6, to a newer release. The challenge is > updating it without an internet connection. The machine cannot be > connected to the internet, so all program dependencies need to be > installed manually. Does anyone k --=-VFEF31YaS3Hv7iO0slol Content-Type: text/html; charset="utf-8" I think the auditd package that ships with 5.3 has a bug.  Use one of the newer versions available from

http://people.redhat.com/sgrubb/audit/index.html

On Mon, 2009-04-27 at 11:15 -1000, Dave Trepanier wrote:
uditd audit.log files stops receiving log entries until the auditd service is stopped and restarted.  The logs entries re-start also after I run audit –f.  I have been thinking about updating auditd , currently release 7.7.7-6, to a newer release.  The challenge is updating it without an internet connection.  The machine cannot be connected to the internet, so all program dependencies need to be installed manually.  Does anyone k
--=-VFEF31YaS3Hv7iO0slol-- --===============0566443364== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0566443364==--