public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Running multiple audit service clients
@ 2016-02-10 21:28 Max Timchenko
  2016-02-11  2:30 ` Richard Guy Briggs
  2016-02-12 18:50 ` Steve Grubb
  0 siblings, 2 replies; 7+ messages in thread
From: Max Timchenko @ 2016-02-10 21:28 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 690 bytes --]

Dear all,

I have a situation where there are two audit clients on the same machine:
one of them is auditd, and another one is an IDS client that uses the audit
subsystem directly. By looking at the source (
http://lxr.free-electrons.com/source/kernel/audit.c?v=3.13#L787), I suspect
that there might be no provision in the kernel for multiple audit subsystem
userland daemons running in parallel (only one pid, only one netlink socket
in the kernel). I could not find any documentation confirming or denying
that.

Has anyone tried that before? What would actually happen if two different
audit clients tried to use the same interface to the audit subsystem in the
kernel?

Yours,
-- 
Max

[-- Attachment #1.2: Type: text/html, Size: 968 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2016-02-12 19:13 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-02-10 21:28 Running multiple audit service clients Max Timchenko
2016-02-11  2:30 ` Richard Guy Briggs
2016-02-11  8:16   ` Paul Moore
2016-02-11 20:19   ` Max Timchenko
2016-02-12  4:39     ` Richard Guy Briggs
2016-02-12 19:13     ` Steve Grubb
2016-02-12 18:50 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox