From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Diskless workstation audit advice Date: Tue, 27 May 2014 11:24:44 -0400 Message-ID: <15571476.jNpUFveSW7@x2> References: <1401136776.18537.13.camel@swtf.swtf.dyndns.org> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1401136776.18537.13.camel@swtf.swtf.dyndns.org> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: burn@swtf.dyndns.org Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Tuesday, May 27, 2014 06:39:36 AM Burn Alting wrote: > My question is: > To collect AND transmit audit until the last possible moment, is the > logical place to perform the last collection and transmission operation > within the 'stop' function of /etc/init.d/auditd ? > > The enrichment (calling ausearch -i) rules out syslog. For sysVinit systems, yes. -Steve