Audit Parsing Library Requirements

Steve Grubb sgrubb at redhat.com
Fri Mar 10 19:32:26 UTC 2006


On Friday 10 March 2006 14:25, LC Bruzenak wrote:
> If not a bother would you mind listing the fields in the record or point
> me to a reference of what they are on your next spec?

We'll make that later in the project. I would need to spend some time going 
over every single message. Amazingly, you can write a parser without knowing 
what all is there since it all follows a well defined pattern.

-Steve




More information about the Linux-audit mailing list