[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]

Re: [RFC][PATCH] collect security labels on user processes generating audit messages



Steve Grubb wrote:
> On Wednesday 15 February 2006 12:17, Linda Knippers wrote:
> 
>>How can I tell from the audit records that the file name was "(null)"
>>vs. having "(null)" manufactured by the audit system?
> 
> 
> ls -i "(null)"
> 
> and then compare inode values.

The inode could be long gone by the time I'm looking at the audit log.

-- ljk


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]