Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* EOE events in auparse output
@ 2016-12-05 13:00 Nikolai Kondrashov
  2016-12-05 15:27 ` Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Nikolai Kondrashov @ 2016-12-05 13:00 UTC (permalink / raw)
  To: linux-audit, Steven Grubb

Hi Steve, everyone,

I was playing with auditd and aushape on Fedora 24 and found some strange
entries in my log. There was a separate *event* produced by auparse containing
a single EOE record. These events had the same serial number as the directly
preceding events, which were exclusively containing SYSCALL records.

Those EOE records didn't appear in the audit.log file.

Is this a bug? Is this normal?

Thank you.

Nick

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-12-05 16:49 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-12-05 13:00 EOE events in auparse output Nikolai Kondrashov
2016-12-05 15:27 ` Steve Grubb
2016-12-05 15:34   ` Nikolai Kondrashov
2016-12-05 15:54     ` Steve Grubb
2016-12-05 16:49       ` Nikolai Kondrashov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox