* Audit slowing system.
@ 2011-05-04 19:41 David Flatley
2011-05-05 12:47 ` Steve Grubb
0 siblings, 1 reply; 4+ messages in thread
From: David Flatley @ 2011-05-04 19:41 UTC (permalink / raw)
To: linux-audit
[-- Attachment #1.1: Type: text/plain, Size: 397 bytes --]
RHEL 4.7 system running Steve Grubb's STIG compliant audit.rules file.
System seems to be struggling to run audit. I run this
config on several systems with no problems. Top does not show anything
that indicates a problem, no directories filling. Any
suggestions on settings to change? It is a 64 bit system with the 32 bit
rules commented out in the rules file.
Thanks.
D Flatley
[-- Attachment #1.2: Type: text/html, Size: 637 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Audit slowing system.
2011-05-04 19:41 Audit slowing system David Flatley
@ 2011-05-05 12:47 ` Steve Grubb
2011-05-05 13:00 ` David Flatley
0 siblings, 1 reply; 4+ messages in thread
From: Steve Grubb @ 2011-05-05 12:47 UTC (permalink / raw)
To: linux-audit
On Wednesday, May 04, 2011 03:41:09 PM David Flatley wrote:
> RHEL 4.7 system running Steve Grubb's STIG compliant audit.rules file.
> System seems to be struggling to run audit. I run this
> config on several systems with no problems. Top does not show anything
> that indicates a problem, no directories filling. Any
> suggestions on settings to change? It is a 64 bit system with the 32 bit
> rules commented out in the rules file.
Are you getting lots of audit events logged? If so, that might point towards a rule
that might need adjusting. Also, stig rules were never shipped (or tested) on RHEL4.
So, I don't know which ones you are using. If the rules do not explicitly add the -F
arch=b64 on the 64 bit rules, that would cause problems.
-Steve
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Audit slowing system.
2011-05-05 12:47 ` Steve Grubb
@ 2011-05-05 13:00 ` David Flatley
2011-05-05 16:02 ` LC Bruzenak
0 siblings, 1 reply; 4+ messages in thread
From: David Flatley @ 2011-05-05 13:00 UTC (permalink / raw)
To: linux-audit
[-- Attachment #1.1: Type: text/plain, Size: 1242 bytes --]
Yes I have had to adjust the rules file for RHEL 4. I have this
running on several RHEL 4 systems with no problems but this system is a
server
running a database. I upped the priority from 3 to 4 and increased the
buffer from 8 to 12 megs. I will recheck for the -F.
Thanks.
D Flatley
From:
Steve Grubb <sgrubb@redhat.com>
To:
linux-audit@redhat.com
Cc:
David Flatley/Burlington/IBM@IBMUS
Date:
05/05/2011 08:48 AM
Subject:
Re: Audit slowing system.
On Wednesday, May 04, 2011 03:41:09 PM David Flatley wrote:
> RHEL 4.7 system running Steve Grubb's STIG compliant audit.rules
file.
> System seems to be struggling to run audit. I run this
> config on several systems with no problems. Top does not show anything
> that indicates a problem, no directories filling. Any
> suggestions on settings to change? It is a 64 bit system with the 32 bit
> rules commented out in the rules file.
Are you getting lots of audit events logged? If so, that might point
towards a rule
that might need adjusting. Also, stig rules were never shipped (or tested)
on RHEL4.
So, I don't know which ones you are using. If the rules do not explicitly
add the -F
arch=b64 on the 64 bit rules, that would cause problems.
-Steve
[-- Attachment #1.2: Type: text/html, Size: 2192 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: Audit slowing system.
2011-05-05 13:00 ` David Flatley
@ 2011-05-05 16:02 ` LC Bruzenak
0 siblings, 0 replies; 4+ messages in thread
From: LC Bruzenak @ 2011-05-05 16:02 UTC (permalink / raw)
To: David Flatley; +Cc: linux-audit
You generally should start with an aureport over the time period you saw
the issue, then drill down from there. But if your audit logs are not
larger than usual maybe this isn't your problem.
What symptoms of struggling are you seeing? You said top shows nothing
out of the ordinary and no directories are getting full (I suppose you
mean /var/log/audit)...so I am not certain what behavior you see that is
leading you towards audit being the problem.
LCB
--
LC (Lenny) Bruzenak
lenny@magitekltd.com
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2011-05-05 16:02 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-05-04 19:41 Audit slowing system David Flatley
2011-05-05 12:47 ` Steve Grubb
2011-05-05 13:00 ` David Flatley
2011-05-05 16:02 ` LC Bruzenak
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox