Re: Audit issues with Snare version 1.5 and RHEL 5.3 x86_64

2009-04-28 Thread Steve Grubb
On Monday 27 April 2009 06:03:48 pm Kevin Boyce wrote: I think the auditd package that ships with 5.3 has a bug. There was a memory leak when specifying the NOLOG format option that was fixed in a RHEL5 release last week. Look for audit-1.7.7-6.el5_3.2.rpm. -Steve -- Linux-audit mailing list

Audit issues with Snare version 1.5 and RHEL 5.3 x86_64

2009-04-27 Thread Dave Trepanier
Hi, Has anybody had issues with using Snare 1.5 with RHEL 5.3 x86_64? The auditd audit.log files stops receiving log entries until the auditd service is stopped and restarted. The logs entries re-start also after I run audit -f. I have been thinking about updating auditd , currently