public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* questions about auditing on a new RH 6 box
@ 2011-01-14 16:21 Tangren, Bill
  2011-01-14 16:42 ` Eric Paris
  0 siblings, 1 reply; 16+ messages in thread
From: Tangren, Bill @ 2011-01-14 16:21 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 563 bytes --]

I have a new VM running RH 6 server. I put some audit.rules in place, and
now I notice that I am getting 11 MB of audit log entries every half hour.
This server has no users or services running. I am trying to use
audit-viewer to determine which of my rules is creating so much log traffic,
but I don't understand the output enough to be able to tell. The version of
audit is 2.0.4-1 (64 bit). 

Is this the correct forum to ask this question? 

If so, I can provide the audit rules and some of the logs.

---
Bill Tangren
IAM
U.S. Naval Observatory, Washington


[-- Attachment #1.2: smime.p7s --]
[-- Type: application/x-pkcs7-signature, Size: 5784 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2011-01-14 19:57 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-14 16:21 questions about auditing on a new RH 6 box Tangren, Bill
2011-01-14 16:42 ` Eric Paris
2011-01-14 17:23   ` Tangren, Bill
2011-01-14 17:35     ` LC Bruzenak
2011-01-14 17:56       ` Tangren, Bill
2011-01-14 18:39         ` LC Bruzenak
2011-01-14 19:04           ` Tangren, Bill
2011-01-14 18:10       ` Tangren, Bill
2011-01-14 19:12         ` Steve Grubb
2011-01-14 19:26           ` Tangren, Bill
2011-01-14 19:57             ` Steve Grubb
2011-01-14 18:58       ` Steve Grubb
2011-01-14 19:07         ` Tangren, Bill
2011-01-14 19:24           ` LC Bruzenak
2011-01-14 19:27             ` Tangren, Bill
2011-01-14 19:39             ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox