# # This file controls the configuration of the audit daemon # ######################################################################### # Change Log: # # Date: Author: Description: #______________ _______________ ________________________________________ # # 10/16/2010 J. Richard Change name_format to HOSTNAME from USER. # remove name argument. This makes the file # generally applicable to all servers. ######################################################################### log_file = /var/log/audit/audit.log log_format = RAW log_group = viewslog priority_boost = 4 flush = INCREMENTAL freq = 25 num_logs = 4 disp_qos = lossy dispatcher = /sbin/audispd name_format = HOSTNAME #name = max_log_file = 5 max_log_file_action = IGNORE space_left = 75 space_left_action = SYSLOG action_mail_acct = root admin_space_left = 50 admin_space_left_action = SYSLOG disk_full_action = SUSPEND disk_error_action = SUSPEND ##tcp_listen_port = tcp_listen_queue = 5 tcp_max_per_addr = 1 ##tcp_client_ports = 1024-65535 tcp_client_max_idle = 0 enable_krb5 = no krb5_principal = auditd ##krb5_key_file = /etc/audit/audit.key