public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* question
@ 2008-10-31 18:21 David Flatley
  2008-10-31 19:50 ` question Steve Grubb
  0 siblings, 1 reply; 9+ messages in thread
From: David Flatley @ 2008-10-31 18:21 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 642 bytes --]


    If you would indulge my simpler in comparison question of the group. I
am setting up audit
on heavy usage systems. I have setup my auditd.conf to rotate the files
once they get to 70
meg and allow up to 12 rotated files. I created a cron that runs hourly to
look and see if
a ninth rotated file exists and if so run "ausearch -i" outputted to a file
and store the
file, then remove the rotated files. I run the cron to avoid losing data if
there is alot of activity
and rotated files are rolled off. I also have to balance performance with
auditing in this
arrangement.
   My question is: is there a better way to do this?
       Thanks.

[-- Attachment #1.2: Type: text/html, Size: 719 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2008-11-03 17:57 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-10-31 18:21 question David Flatley
2008-10-31 19:50 ` question Steve Grubb
2008-11-02 17:24   ` question David Flatley
2008-11-03  2:42     ` question David Flatley
2008-11-03 14:15       ` question Steve Grubb
2008-11-03 17:21         ` question David Flatley
2008-11-03 17:57           ` question Steve Grubb
2008-11-02 18:25   ` question LC Bruzenak
2008-11-03  3:54     ` question David Flatley

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox