Should open syscall records occur without a path record?

John D. Ramsdell ramsdell at mitre.org
Mon Jul 23 19:41:31 UTC 2007


Steve Grubb <sgrubb at redhat.com> writes:

> OK good. That is a known problem (bz 235398) that should be worked
> on right after we get the improved dispatcher finished.

Hmm.  I'm wedged if I cannot process open system call records.  I bet
I can quickly write some script that interchanges adjacent audit
records that are out of order in the raw logs, so as to allow me to
proceed.  If someone else has a record sorter, please send it along.

John




More information about the Linux-audit mailing list