From mboxrd@z Thu Jan 1 00:00:00 1970 From: Laurent Bigonville Subject: Re: aulast only displaying reboot pseudo-users Date: Tue, 17 Jun 2014 16:09:32 +0200 Message-ID: <20140617160932.1e12ac53@soldur.bigon.be> References: <20140605000405.687f6ad7@fornost.bigon.be> <20140614135319.18680d6f@fornost.bigon.be> <1402953610.11087.5.camel@localhost> <2733072.zhBU5hVyYr@x2> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <2733072.zhBU5hVyYr@x2> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com Le Tue, 17 Jun 2014 09:29:21 -0400, Steve Grubb a =E9crit : > On Monday, June 16, 2014 05:20:10 PM Eric Paris wrote: [...] > > I'd call this a pretty clear userspace bug where it just completely > > drops records, even if it can't parse them... > = > That theory can be tested by using: > = > ausearch --start this-week --debug > /dev/null > = > Anything that gets tossed out will be reported to stderr. I'm getting indeed quite a lot of skipped event: Malformed event skipped, rc=3D7. type=3DLOGIN msg=3Daudit(1402934401.462:16= 26): pid=3D1719 uid=3D0 old-auid=3D4294967295 new-auid=3D0 old-ses=3D429496= 7295 new-ses=3D121 res=3D1 > = > -Steve