From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Bill Tangren" Subject: Re: auditing for RHEL ES4 Date: Fri, 16 Nov 2007 11:41:21 -0500 (EST) Message-ID: <4670.10.1.5.75.1195231281.squirrel@aa.usno.navy.mil> References: <4558.10.1.5.75.1195228480.squirrel@aa.usno.navy.mil> <200711161124.34339.sgrubb@redhat.com> Mime-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Return-path: Received: from mx3.redhat.com (mx3.redhat.com [172.16.48.32]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id lAGGfRKH031235 for ; Fri, 16 Nov 2007 11:41:27 -0500 Received: from aa.usno.navy.mil (beatrix.usno.navy.mil [198.116.61.254]) by mx3.redhat.com (8.13.1/8.13.1) with ESMTP id lAGGfQ5k016785 for ; Fri, 16 Nov 2007 11:41:26 -0500 In-Reply-To: <200711161124.34339.sgrubb@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On DATE, the author spaketh: Steve Grubb > On Friday 16 November 2007 10:54:40 Bill Tangren wrote: >> The reports always cover the entire range of available logs (sometimes >> gigabytes of data). The reports can take a LONG time to compile, and i= t >> doesn't give me the daily snapshot I need. > > Use the -ts and -te commandline options to limit the report range. It > requires > the date format to be correct for your locale - iow date "+%x %T". Th= e > older version does not support words like today or yesterday. > I see. So I misunderstood what you said when I asked about this before. Thanks, Steve! > >> I'm thinking of installing the latest tarball and compiling, as I >> understand >> more recent versions of aureport have implemented time limits. > > The older one does, too. > > >> My question now is, is it possible to uninstall the prepackaged audit >> and >> audit-lib, and install the latest from source, without seriously hosin= g >> my >> system? > > No, it will not work. RHEL4 (and derivatives) has to use the 1.0.X seri= es > of > audit packages. > > -Steve > --=20 Bill Tangren U.S. Naval Observatory