audit.63 kernel.

David Woodhouse dwmw2 at infradead.org
Mon Jun 20 15:16:28 UTC 2005


On Mon, 2005-06-20 at 11:09 -0400, Steve Grubb wrote:
> There is something new that I noticed...all the SYSCALL messages have items=1. 
> It didn't used to be this way. It used to be the number of aux records 
> associated with the syscall event.

It's always been the number of _names_ associated with the syscall,
hasn't it? Try sys_rename().

-- 
dwmw2




More information about the Linux-audit mailing list