expected performance hit for logging all execve's?

Peter Moody pmoody at google.com
Fri Jan 20 20:06:13 UTC 2012


I'm trying to run some tests so I can find locally relevant numbers,
but I was wondering if you had any idea what sort of performance hit
I'd be incurring by logging every successful execve.

To be sure, I consider this a bad idea and I'm actually looking to
disuade people of it.

Cheers,
peter

-- 
Peter Moody      Google    1.650.253.7306
Security Engineer  pgp:0xC3410038




More information about the Linux-audit mailing list