I am configuring our auditing service to send logs through rsyslog. While tinkering around, I was able to stop and start auditing from the command line as the root user. Is there a way to prevent anyone including root from stopping the audit service unless system is rebooted into single user mode? Thanks, Paul M. Whitney