* Auditd.conf settings for Satellite 6 server
@ 2017-03-30 15:40 Fulda, Paul R [US] (MS)
2017-03-30 15:59 ` Steve Grubb
0 siblings, 1 reply; 2+ messages in thread
From: Fulda, Paul R [US] (MS) @ 2017-03-30 15:40 UTC (permalink / raw)
To: linux-audit@redhat.com
[-- Attachment #1.1: Type: text/plain, Size: 401 bytes --]
All,
Can someone give me some optimized auditd.conf settings for a Red Hat Satellite 6 server running on Red Hat 7.3? When I am creating and updating content views on satellite, auditd cannot keep up and bogs the system to a halt. The audit.rules file is configured for DISA security settings so it's looking at a lot of things. Any help would be much appreciated.
Thanks,
Paul Fulda
[-- Attachment #1.2: Type: text/html, Size: 2314 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Auditd.conf settings for Satellite 6 server
2017-03-30 15:40 Auditd.conf settings for Satellite 6 server Fulda, Paul R [US] (MS)
@ 2017-03-30 15:59 ` Steve Grubb
0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2017-03-30 15:59 UTC (permalink / raw)
To: linux-audit
On Thursday, March 30, 2017 11:40:31 AM EDT Fulda, Paul R [US] (MS) wrote:
> Can someone give me some optimized auditd.conf settings for a Red Hat
> Satellite 6 server running on Red Hat 7.3? When I am creating and updating
> content views on satellite, auditd cannot keep up and bogs the system to a
> halt. The audit.rules file is configured for DISA security settings so
> it's looking at a lot of things. Any help would be much appreciated.
For one, you can set the flush mode in auditd.conf to INCREMENTAL_ASYNC and it
should allow you to completely fill up your disks in a hurry without bogging
down the system. Also set freq to something like 250.
I would then take a look at the key report during that time to see what event
is getting triggered.
aureport --start xxx --end yyy --key --summary
Where xxx is start of this burst and yyy is end of this burst. (More than
likely its some rule watching deletes which is not very useful.) Once you know
which rule is getting triggered I think we can talk about how to minimize the
events.
-Steve
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-03-30 15:59 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-03-30 15:40 Auditd.conf settings for Satellite 6 server Fulda, Paul R [US] (MS)
2017-03-30 15:59 ` Steve Grubb
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).