ausearch notes

Steve Grubb sgrubb at redhat.com
Mon Jun 2 14:50:33 UTC 2008


On Friday 30 May 2008 17:12:25 LC Bruzenak wrote:
> The "-i" flag on ausearch appears to remove the "node=" info when the
> type!=UNKNOWN:

Thanks for reporting this. It appears to be a long standing bug in that I 
don't think the code was ever put into place to do the right thing. I can see 
this in 1.6.5 and that's as far back as I checked. This will be fixed in the 
next release.

-Steve




More information about the Linux-audit mailing list