Hide Forgot
Description of problem: When a node name is a part of audit message and its length is bigger than usually (~80 characters) then auparse fails to parse the rest of message. This can lead even to 'hidden' audit events. Version-Release number of selected component (if applicable): audit-2.1.3-3.el6 How reproducible: 100% Steps to Reproduce: # cat >log<<-EOF node=1234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890 type=DAEMON_ACCEPT msg=audit(1320238076.308:8675): addr=10.16.66.107:52363 port=52363 res=success EOF # ausearch -if log Actual results: <no matches> Expected results: ---- time->Wed Dec 31 22:40:02 1969 node=1234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890 type=DAEMON_ACCEPT msg=audit(1320238076.308:8675): addr=10.16.66.107:52363 port=52363 res=success Additional info: This problem has been originally reported as [1] and immediately resolved with [2] raising node name limit from ~80 to ~340 characters. [1] https://www.redhat.com/archives/linux-audit/2012-March/msg00005.html [2] https://fedorahosted.org/audit/changeset/671
audit-2.2-2.el6 was built to fix this issue.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0929.html