Should open syscall records occur without a path record?

Steve Grubb sgrubb at redhat.com
Tue Jul 24 21:30:31 UTC 2007


On Tuesday 24 July 2007 08:06:44 am John D. Ramsdell wrote:
> Also, I notice that in
> just one message, the msg field value does not end with a colon:
>
> type=DAEMON_START msg=audit(1185203485.586:824) auditd start, ver=1.5.5,
> format=raw, auid=500 pid=24638 res=success, auditd pid=24638

Actually, it looks like all the DAEMON_  records are missing a ':' after the 
timestamp. The parsers are not exactly looking for it, but I'll add it for 
consistency.

-Steve




More information about the Linux-audit mailing list