public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: Audit not taking rules
Date: Thu, 3 Jul 2008 07:49:07 -0400	[thread overview]
Message-ID: <200807030749.07390.sgrubb@redhat.com> (raw)
In-Reply-To: <d96bd5b70807021544t44623c2lcffaa80d4a0d79b1@mail.gmail.com>

On Wednesday 02 July 2008 18:44:49 Bo wrote:
> I have RHEL 4 install (update 5).
>
> [root@master ~]# service auditd restart
> Stopping auditd:                                           [  OK  ]
> Starting auditd:                                           [  OK  ]
> Error sending watch insert request (Invalid argument)
> There was an error in line 26 of /etc/audit.rules

What is in line 26 of the rules?


> Can anyone point me to a solution?
> audit version 1.0.15
> kernel 2.6.22.5

This is not a RHEL4 kernel. You need to use RHEL4's kernel with the RHEL4 user 
space audit tools. This is undoubtedly the problem. The audit system evolved 
over time and some things were deprecated and some things were added. The 
user space tools hide this as long as you use the right ones.

-Steve

      reply	other threads:[~2008-07-03 11:49 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-07-02 22:44 Audit not taking rules Bo
2008-07-03 11:49 ` Steve Grubb [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200807030749.07390.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox