Bug 1921658

Summary: Ausearch fails to correctly parse an event whose timestamp appears more than 2 seconds later than co-located events
Product: Red Hat Enterprise Linux 8 Reporter: Lukas Vrabec <lvrabec>
Component: auditAssignee: Sergio Correia <scorreia>
Status: CLOSED ERRATA QA Contact: Martin Zelený <mzeleny>
Severity: unspecified Docs Contact: Khushbu Borole <kborole>
Priority: unspecified    
Version: ---CC: burn, dapospis, lvrabec, mzeleny, qe-baseos-security, scorreia, sgrubb
Target Milestone: rcKeywords: AutoVerified, Triaged
Target Release: 8.0   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: audit-3.0.5-1.el8 Doc Type: Enhancement
Doc Text:
.Audit now provides options for specifying the end of the event timeout With this release, the `ausearch` tool supports the `--eoe-timeout` option, and the `auditd.conf` file contains the `end_of_event_timeout` option. You can use these options to specify the end of the event timeout to avoid problems with parsing co-located events. The default value for the end of the event timeout is set to two seconds.
Story Points: ---
Clone Of: 1914603 Environment:
Last Closed: 2022-05-10 15:30:12 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1914603, 1939406    
Bug Blocks:    

Comment 1 Sergio Correia 2021-02-05 12:31:51 UTC
PR upstream: https://github.com/linux-audit/audit-userspace/pull/150

Comment 16 errata-xmlrpc 2022-05-10 15:30:12 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (audit bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:2096