Should open syscall records occur without a path record?
John D. Ramsdell
ramsdell at mitre.org
Mon Jul 23 19:41:31 UTC 2007
Steve Grubb <sgrubb at redhat.com> writes:
> OK good. That is a known problem (bz 235398) that should be worked
> on right after we get the improved dispatcher finished.
Hmm. I'm wedged if I cannot process open system call records. I bet
I can quickly write some script that interchanges adjacent audit
records that are out of order in the raw logs, so as to allow me to
proceed. If someone else has a record sorter, please send it along.
John
More information about the Linux-audit
mailing list