linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* kauditd is writing too many lines in syslog
@ 2014-01-20  4:45 Aaron Lewis
  2014-01-20  5:11 ` Aaron Lewis
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Aaron Lewis @ 2014-01-20  4:45 UTC (permalink / raw)
  To: linux-audit@redhat.com

Hi,

I'm not sure if this is the default behavior,

I'm using audit 2.3.2, and I've configured auditd not to log anything
(NOLOG option), and I set the queue buffer to 10240 messages.

When the buffer is full or auditd is suddenly killed or for some other
reason, it seems to write a lot of things to dmesg or
/var/log/messages

So, did kauditd wrote all these? I already killed auditd process but I
can still see logs piling up.

Can I ask kauditd not print anything if user space program cannot
handle that much message?

-- 
Best Regards,
Aaron Lewis - PGP: 0x13714D33 - http://pgp.mit.edu/
Finger Print:   9F67 391B B770 8FF6 99DC  D92D 87F6 2602 1371 4D33

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2014-01-20 20:43 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-01-20  4:45 kauditd is writing too many lines in syslog Aaron Lewis
2014-01-20  5:11 ` Aaron Lewis
2014-01-20 17:36 ` Richard Guy Briggs
2014-01-20 17:40   ` Steve Grubb
2014-01-20 18:24     ` Richard Guy Briggs
2014-01-20 18:34       ` Aaron Lewis
2014-01-20 20:43 ` Eric Paris

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).