public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Events lost with dispatcher
@ 2010-03-31 19:07 Vishwanath Venkatesan
  2010-03-31 19:26 ` Steve Grubb
  0 siblings, 1 reply; 7+ messages in thread
From: Vishwanath Venkatesan @ 2010-03-31 19:07 UTC (permalink / raw)
  To: linux-audit

Hi,

I having troubles receiving events with the dispatcher in ubuntu-9.04.

I am just trying to use the rule
-a entry, always -S execve -S exit_group
I receive all the events in the audit.log, but not in the dispatcher.
I am using the dispatcher code in the auditd website.

I also using two threads where in one thread collects all the data and  
the other thread does the parsing.
So there is no blocking and the queue is an unbounded concurrent queue.
I don't think there can't anything else done at the receiving end.

If anyone has faced something similar or have suggestions, please let  
me know

Thanks
Vish

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2010-04-07 13:00 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-03-31 19:07 Events lost with dispatcher Vishwanath Venkatesan
2010-03-31 19:26 ` Steve Grubb
2010-03-31 19:32   ` Vishwanath Venkatesan
2010-03-31 19:48     ` Steve Grubb
2010-03-31 19:56       ` Steve Grubb
2010-04-07 12:44         ` Matthew Booth
2010-04-07 13:00           ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox