From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: FW: Time field not readable Date: Mon, 3 Nov 2008 16:45:46 -0500 Message-ID: <200811031645.46543.sgrubb@redhat.com> References: <954E3479CC27224785179CA04904214D0B23E043@0668-its-exmp01.us.saic.com> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <954E3479CC27224785179CA04904214D0B23E043@0668-its-exmp01.us.saic.com> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com Cc: "Kirkwood, David A." List-Id: linux-audit@redhat.com On Monday 03 November 2008 14:59:05 Kirkwood, David A. wrote: > I have removed the packages audit-2.4.1, audit-libs-2.4.1, > audit-libs-devel-2,4,1 I have no idea what those are. the latest RHEL4 audit package is 1.0.16 and RHEL5 is 1.6.5. My development copy is 1.7.9. You have a RHEL4 system that is way out of whack since those are packages that I've never heard of. :) > and SnareLinux and added via rpm audit-libs-1.0.14-1, audit-libs-1.0.4-1 and > audit-1.0.14-1. The time field is still not readable when I used ausearch or > aureport utilities. Updating the user space utilities means that from now on your logs will be readable. Also, what kernel are you running? Are you running a real RHEL4 kernel? -Steve