Diskless workstation audit advice

Steve Grubb sgrubb at redhat.com
Tue May 27 15:24:44 UTC 2014


On Tuesday, May 27, 2014 06:39:36 AM Burn Alting wrote:
> My question is:
> To collect AND transmit audit until the last possible moment, is the
> logical place to perform the last collection and transmission operation
> within the 'stop' function of /etc/init.d/auditd ?
> 
> The enrichment (calling ausearch -i) rules out syslog.

For sysVinit systems, yes.

-Steve




More information about the Linux-audit mailing list