public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* buffer space
@ 2009-08-13 14:56 David Flatley
  2009-08-13 15:29 ` Matthew Booth
  2009-08-13 18:28 ` Steve Grubb
  0 siblings, 2 replies; 34+ messages in thread
From: David Flatley @ 2009-08-13 14:56 UTC (permalink / raw)
  To: Linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1108 bytes --]


  Red Hat 5.3 running audit 1.7.7-6
Rotating logs at 20 megs and allowing 8 logs
Rules have watches and syscalls from the SECSCAN recommendations, and have
added some of Steve Grubb's recommendations.
When we extract and archive the audit logs we get "Error receiving audit
netlink packet (No buffer space available) an "error sending signal info
request"
Our extract is: stop auditd then create a file and run ausearch -i > file
then run an aureport -i > file then once that is done we delete all the
logs and restart auditd.
If I run this manually it works fine but if I have it running it in a cron
we get Kernel panics, lockups and log data loss plus the buffer messages.
I added "-r 0" to the audit.rules but it does not seem to work. We run a
very similar configuration on Red Hat ES and AS 4 with no problems.
We are testing the subject systems and running a looping regression test
that can fill the audit logs in a little over an hour at the present
settings.
Thoughts or ideas??
 Thanks.

David Flatley CISSP
I.T. Specialist, Managing Consultant
Member: ISC2, ISACA, Center for Internet Security


[-- Attachment #1.2: Type: text/html, Size: 1233 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 34+ messages in thread

end of thread, other threads:[~2009-08-27 18:45 UTC | newest]

Thread overview: 34+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-13 14:56 buffer space David Flatley
2009-08-13 15:29 ` Matthew Booth
2009-08-13 18:28 ` Steve Grubb
2009-08-17 14:49   ` David Flatley
2009-08-17 15:07     ` Steve Grubb
2009-08-17 15:36       ` Norman Mark St. Laurent
2009-08-17 16:38       ` David Flatley
2009-08-17 16:52         ` LC Bruzenak
2009-08-17 17:06           ` David Flatley
2009-08-17 17:15             ` LC Bruzenak
2009-08-17 17:24               ` LC Bruzenak
2009-08-17 21:18                 ` David Flatley
2009-08-17 17:32               ` David Flatley
2009-08-17 17:46                 ` LC Bruzenak
2009-08-17 18:01                   ` Steve Grubb
2009-08-17 18:13                     ` Norman Mark St. Laurent
2009-08-17 18:14                     ` LC Bruzenak
2009-08-17 18:46                       ` Norman Mark St. Laurent
2009-08-17 19:37                         ` Steve Grubb
2009-08-17 19:46                           ` Norman Mark St. Laurent
2009-08-18 13:02                           ` David Flatley
2009-08-18 15:09                             ` LC Bruzenak
2009-08-18 15:53                               ` Steve Grubb
2009-08-27 17:21                           ` David Flatley
2009-08-27 17:32                             ` Steve Grubb
2009-08-27 17:45                               ` David Flatley
2009-08-27 18:45                                 ` Steve Grubb
2009-08-27 17:33                             ` LC Bruzenak
2009-08-23  4:12       ` D.A. Muran-de Assereto
2009-08-17 15:34     ` Norman Mark St. Laurent
2009-08-17 16:58       ` Mike Nixon
2009-08-23  4:32         ` David Muran-de Assereto
2009-08-23 16:12           ` Mike Nixon
2009-08-23 20:24             ` David Muran-de Assereto

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox