I've attached another ausearch output which makes aureport to hang on
100% usage.
type=CONFIG_CHANGE msg=audit(1477974302.999:714974): auid=0 ses=59247 
op="updated rules" path="/var/log/wtmp" key=6163636573730173657373696F6E list=4 
res=1
type=SYSCALL msg=audit(1477974302.999:714975): arch=c000003e syscall=82 
success=yes exit=0 a0=e1a490 a1=e262d0 a2=e1a490 a3=84 items=4 ppid=9347 
pid=9348 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 
tty=(none) ses=59247 comm="logrotate" exe="/usr/sbin/logrotate" 
key=6163636573730173657373696F6E
type=CWD msg=audit(1477974302.999:714975):  cwd="/"
type=PATH msg=audit(1477974302.999:714975): item=0 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974302.999:714975): item=1 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974302.999:714975): item=2 name="/var/log/wtmp" 
inode=5246306 dev=fe:00 mode=0100664 ouid=0 ogid=43 rdev=00:00 nametype=DELETE
type=PATH msg=audit(1477974302.999:714975): item=3 name="/var/log/wtmp.1" 
inode=5246306 dev=fe:00 mode=0100664 ouid=0 ogid=43 rdev=00:00 nametype=CREATE
type=PROCTITLE msg=audit(1477974302.999:714975): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=CONFIG_CHANGE msg=audit(1477974302.999:714976): auid=0 ses=59247 
op="updated rules" path="/var/log/wtmp" key=6163636573730173657373696F6E list=4 
res=1
type=SYSCALL msg=audit(1477974302.999:714977): arch=c000003e syscall=2 
success=yes exit=3 a0=e1a490 a1=200c2 a2=180 a3=84 items=2 ppid=9347 pid=9348 
auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) 
ses=59247 comm="logrotate" exe="/usr/sbin/logrotate" 
key=6163636573730173657373696F6E
type=CWD msg=audit(1477974302.999:714977):  cwd="/"
type=PATH msg=audit(1477974302.999:714977): item=0 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974302.999:714977): item=1 name="/var/log/wtmp" 
inode=5244346 dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=CREATE
type=PROCTITLE msg=audit(1477974302.999:714977): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974302.999:714978): arch=c000003e syscall=91 
success=yes exit=0 a0=3 a1=180 a2=180 a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974302.999:714978): item=0 name=(null) inode=5244346 
dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974302.999:714978): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974302.999:714979): arch=c000003e syscall=93 
success=yes exit=0 a0=3 a1=0 a2=2b a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974302.999:714979): item=0 name=(null) inode=5244346 
dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974302.999:714979): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974302.999:714980): arch=c000003e syscall=91 
success=yes exit=0 a0=3 a1=1b4 a2=2b a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974302.999:714980): item=0 name=(null) inode=5244346 
dev=fe:00 mode=0100600 ouid=0 ogid=43 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974302.999:714980): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=CONFIG_CHANGE msg=audit(1477974303.003:714981): auid=0 ses=59247 
op="updated rules" path="/var/log/btmp" key=6163636573730173657373696F6E list=4 
res=1
type=SYSCALL msg=audit(1477974303.003:714982): arch=c000003e syscall=82 
success=yes exit=0 a0=e1c010 a1=e26270 a2=e1c010 a3=84 items=4 ppid=9347 
pid=9348 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 
tty=(none) ses=59247 comm="logrotate" exe="/usr/sbin/logrotate" 
key=6163636573730173657373696F6E
type=CWD msg=audit(1477974303.003:714982):  cwd="/"
type=PATH msg=audit(1477974303.003:714982): item=0 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974303.003:714982): item=1 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974303.003:714982): item=2 name="/var/log/btmp" 
inode=5247914 dev=fe:00 mode=0100600 ouid=0 ogid=43 rdev=00:00 nametype=DELETE
type=PATH msg=audit(1477974303.003:714982): item=3 name="/var/log/btmp.1" 
inode=5247914 dev=fe:00 mode=0100600 ouid=0 ogid=43 rdev=00:00 nametype=CREATE
type=PROCTITLE msg=audit(1477974303.003:714982): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=CONFIG_CHANGE msg=audit(1477974303.003:714983): auid=0 ses=59247 
op="updated rules" path="/var/log/btmp" key=6163636573730173657373696F6E list=4 
res=1
type=SYSCALL msg=audit(1477974303.003:714984): arch=c000003e syscall=2 
success=yes exit=3 a0=e1c010 a1=200c2 a2=180 a3=84 items=2 ppid=9347 pid=9348 
auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) 
ses=59247 comm="logrotate" exe="/usr/sbin/logrotate" 
key=6163636573730173657373696F6E
type=CWD msg=audit(1477974303.003:714984):  cwd="/"
type=PATH msg=audit(1477974303.003:714984): item=0 name="/var/log/" 
inode=5243029 dev=fe:00 mode=040755 ouid=0 ogid=0 rdev=00:00 nametype=PARENT
type=PATH msg=audit(1477974303.003:714984): item=1 name="/var/log/btmp" 
inode=5244875 dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=CREATE
type=PROCTITLE msg=audit(1477974303.003:714984): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974303.003:714985): arch=c000003e syscall=91 
success=yes exit=0 a0=3 a1=180 a2=180 a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974303.003:714985): item=0 name=(null) inode=5244875 
dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974303.003:714985): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974303.003:714986): arch=c000003e syscall=93 
success=yes exit=0 a0=3 a1=0 a2=2b a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974303.003:714986): item=0 name=(null) inode=5244875 
dev=fe:00 mode=0100600 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974303.003:714986): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66
type=SYSCALL msg=audit(1477974303.003:714987): arch=c000003e syscall=91 
success=yes exit=0 a0=3 a1=1b0 a2=2b a3=84 items=1 ppid=9347 pid=9348 auid=0 
uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=59247 
comm="logrotate" exe="/usr/sbin/logrotate" key=6163636573730173657373696F6E
type=PATH msg=audit(1477974303.003:714987): item=0 name=(null) inode=5244875 
dev=fe:00 mode=0100600 ouid=0 ogid=43 rdev=00:00 nametype=NORMAL
type=PROCTITLE msg=audit(1477974303.003:714987): 
proctitle=2F7573722F7362696E2F6C6F67726F74617465002F6574632F6C6F67726F746174652E636F6E66

Reply via email to