buffer space

LC Bruzenak lenny at magitekltd.com
Mon Aug 17 16:52:52 UTC 2009


On Mon, 2009-08-17 at 12:38 -0400, David Flatley wrote:\
> 
> I am in error, I meant space_left_action because there is an exec for
> this.
> I was going to do the "service auditd rotate" then move all the
> audit.log.* to
> another directory so that ausearch -i and aureport -i could run on the
> logs. 

David,

I do not think this is entirely accurate.
It is one of my own issues. I am doing the same type thing.
This is necessary on a system with large amounts of audit data (as
aggregated systems tend to be).
I am also moving stuff out of the standard directory.
However, IIUC, the ausearch options will only work on specific files.
If you move the rotated files off to another directory you will lose the
ability to search the directory with a single ausearch command. If there
were a "-id" option (input directory, or similar) which allowed this I
believe it would work better.

Otherwise you could possibly cat the files into one large one, but this
is not optimal IMHO.

Steve recently patched the disk threshold code to auto-reset, which is
nice. You probably want this; it sounds as if we are doing similar
functions. I also have SECSCN issues/mitigations.

LCB.

-- 
LC (Lenny) Bruzenak
lenny at magitekltd.com




More information about the Linux-audit mailing list