Bug 1257650
Summary: | Rebase audit package | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Steve Grubb <sgrubb> |
Component: | audit | Assignee: | Steve Grubb <sgrubb> |
Status: | CLOSED ERRATA | QA Contact: | Ondrej Moriš <omoris> |
Severity: | medium | Docs Contact: | Robert Krátký <rkratky> |
Priority: | high | ||
Version: | 6.7 | CC: | bryanlharris, ksrot, mtessun, omoris, pmoore, pvrabec, qe-baseos-security, rkratky, salmy, sgrubb, ssekidde |
Target Milestone: | rc | Keywords: | Rebase |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | audit-2.4.5-1.el6 | Doc Type: | Rebase: Bug Fixes and Enhancements |
Doc Text: |
_audit_ rebased to version 2.4.5
The _audit_ package, which provides the user-space utilities for storing and searching the audit records generated by the *audit* subsystem in the Linux kernel, has been rebased to version 2.4.5. This update includes enhanced event interpretation facilities that provide more system-call names and arguments to make the understanding of events easier.
This update also has an important behavior change in the way that *auditd* records events to disk. If you are using either `data` or `sync` modes for the *flush* setting in *auditd.conf*, you will see a performance decrease in *auditd's* ability to log events. This is because it was previously not properly informing the kernel that full synchronous writes should be used. This was corrected, which has improved the reliability of the operation, but this has come at the expense of performance. If the performance drop is not tolerable, the *flush* setting should be changed to `incremental` and the *freq* setting will control how often *auditd* instructs the kernel to synchronize all records to disk. A *freq* setting of `100` should give good performance while making sure that new records are flushed to disk periodically.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-05-11 00:02:00 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1271982 |
Description
Steve Grubb
2015-08-27 14:33:40 UTC
*** Bug 1266143 has been marked as a duplicate of this bug. *** Hi Steve, This bug was flagged as requiring a Release Note. Could you please fill out the Doc Text field? I'll edit it into a RN and make sure it gets published. Thank you. Thanks, Steve. Successfully verified, I tried to verify as much as possible from changelog [1] between version 2.3.7 and 2.4.5. Both Sanity and Regression testing passed. [1] https://people.redhat.com/sgrubb/audit/ChangeLog *** Bug 1327286 has been marked as a duplicate of this bug. *** Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-0867.html |