All of lore.kernel.org
 help / color / mirror / Atom feed
* auditd.cron
@ 2017-03-22 21:19 warron.french
  2017-03-22 21:48 ` auditd.cron Steve Grubb
  2017-03-23 14:45 ` auditd.cron Ryan Sawhill
  0 siblings, 2 replies; 6+ messages in thread
From: warron.french @ 2017-03-22 21:19 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1013 bytes --]

So, I needed a feature over 8 months ago, nobody could provide one for the
following:
       Rolling log files either when they hit a certain size or the day
changed over at midnight.

I know that I could have rolled the files at a specific size, by using the
*max_log_file* attribute as identified in the */etc/audit/auditd.conf*, but
there was no "builtin" for managing auto rotation at the start of a new day
(0000 hrs).

It looks like there is a file called */usr/share/doc/auditd-<**version>*
*/auditd.cron*

*.*
To me*, *this file is new; considering I needed it 8 months ago.

*Anyway, how is this file implemented? * Simply move it to a directory with
permissions to execute; ensure it is executable and then simply set up a
cronjob to execute it at whatever time of day that I wish?

*Finally, if I have '-e 2' as the last control in the audit.rules file;
will the auditd.cron which executes as service auditd rotate still function
properly?*

Thanks in advance,
--------------------------
Warron French

[-- Attachment #1.2: Type: text/html, Size: 2020 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2017-03-23 16:11 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-03-22 21:19 auditd.cron warron.french
2017-03-22 21:48 ` auditd.cron Steve Grubb
2017-03-23 13:28   ` auditd.cron Ed Christiansen MS
2017-03-23 13:53     ` auditd.cron Simon Sekidde
2017-03-23 16:11       ` auditd.cron Steve Grubb
2017-03-23 14:45 ` auditd.cron Ryan Sawhill

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.