From: Richard Guy Briggs <rgb@redhat.com>
To: Lenny Bruzenak <lenny@magitekltd.com>
Cc: linux-audit@redhat.com
Subject: Re: Backlog not working with kernel 3.10
Date: Wed, 17 Mar 2021 12:06:14 -0400 [thread overview]
Message-ID: <20210317160614.GV986374@madcap2.tricolour.ca> (raw)
In-Reply-To: <9800e9b0-0cea-d235-0c2e-ec82464520f7@magitekltd.com>
On 2021-03-17 09:32, Lenny Bruzenak wrote:
> On 3/16/21 8:46 PM, Richard Guy Briggs wrote:
>
> >> I have run some simple commands in /data that should be logged , e.g.
> >> touch file, mkdir dir. Finally, I have run auditctl-s and expected to see
> >> the backlog events counter go up, but it's still 0. If I start auditd
> >> again, the events are never logged. Am I missing something here?
> > So, since you haven't indicated if you have tried and tested this
> > already, please start by running those simple commands while the auditd
> > service is running and verifying that those commands do get logged as
> > expected. If they don't, fix that first.
>
> I was wondering if the events are delivered to syslog
> (/var/log/messages) instead while the auditd is down?
>
> Mine are, same kernel version 3.10.0. From the kernel perspective, no
> backlog?. However, if I stop both audit and rsyslog, add some events the
> backlog count doesn't increase and I can't see where the events may have
> been delivered.
If audit is enabled, but auditd isn't registered, it should fill the
backlog since rsyslog and journald aren't considered reliable delivery
even if those messages appear in the latter two.
> LCB
- RGB
--
Richard Guy Briggs <rgb@redhat.com>
Sr. S/W Engineer, Kernel Security, Base Operating Systems
Remote, Ottawa, Red Hat Canada
IRC: rgb, SunRaycer
Voice: +1.647.777.2635, Internal: (81) 32635
--
Linux-audit mailing list
Linux-audit@redhat.com
https://listman.redhat.com/mailman/listinfo/linux-audit
next prev parent reply other threads:[~2021-03-17 16:06 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-03-16 21:25 Backlog not working with kernel 3.10 Alan Evangelista
2021-03-16 21:58 ` Paul Moore
2021-03-17 8:40 ` Alan Evangelista
2021-03-17 19:46 ` Paul Moore
2021-03-17 1:46 ` Richard Guy Briggs
[not found] ` <CAKz+TUsv2p3RM-Em=w3fcMP8ANQZt-H=NOMAxudGhNgjDWLRrw@mail.gmail.com>
2021-03-17 8:36 ` Fwd: " Alan Evangelista
2021-03-17 14:32 ` Lenny Bruzenak
2021-03-17 16:06 ` Richard Guy Briggs [this message]
2021-03-17 16:03 ` Richard Guy Briggs
2021-03-17 20:56 ` Alan Evangelista
2021-03-18 1:16 ` Richard Guy Briggs
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210317160614.GV986374@madcap2.tricolour.ca \
--to=rgb@redhat.com \
--cc=lenny@magitekltd.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox