public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Auditd errors on busy hosts when rolling over log files
@ 2013-11-04  8:46 Burn Alting
  2013-11-04 13:24 ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: Burn Alting @ 2013-11-04  8:46 UTC (permalink / raw)
  To: linux-audit

Hi,

I have some quite busy hosts, that emit the following errors when I
request the audit log file is rolled over (via a kill -s USR1
auditdpid).

  Error receiving audit netlink packet(No buffer space available)
  Error sending signal_info request (No buffer space available)

>From reading earlier posts (circa 2009) it would appear my options are

a. Increase backlog buffer (currently 32768)
b. Increase priority_boost (currently 4)
c. Reduce the number of log files (currently 9)

Does anyone have a feel for which of the above should offer the best
return?

Are their other configuration parameters I could adjust (aside from
changing my ruleset in audit.rules)?

Thanks in advance

Burn

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2013-11-05 13:59 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-11-04  8:46 Auditd errors on busy hosts when rolling over log files Burn Alting
2013-11-04 13:24 ` Steve Grubb
2013-11-05 11:07   ` Burn Alting
2013-11-05 13:59     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox