audit more syscalls during boot before auditd starts?

Giang Nguyen cauthu at gmail.com
Mon Jul 23 14:42:04 UTC 2012


> But even if you successfully load rules early...you need a daemon to collect
> the results before the internal kernel buffer overflows and forever lose the
> events. So, this means getting the audit daemon running earlier and its main
> requirement is the MAC policy already be loaded and the disk system mounted
> (perhaps networking running if you use remote logging).

Thanks, Steve.




More information about the Linux-audit mailing list