1. Manuals
  2. Brands
  3. Computer Equipment
  4. Server
  5. IBM
  6. Computer Equipment
  7. Server

IBM 10 SP1 EAL4 - page 150

1 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 246
Download on canonical page 246 pages, 2.94 Mb
Option Description Possible values
log_file name of the log file
log_format How to flush the data from
auditd to the log.
RAW. Only RAW is supported in this version.
priority_boost The nice value for auditd.
Used to run auditd at a
certain priority.
flush Method of writing data to disk. none, interval, data, sync
freq Used when flush is
incremental, states how many
records written before a forced
flush to disk.
num_logs Number of log files to use
max_log_file Maximum log size in
megabytes.
max_log_file_action Action to take when the
maximum log space is reached.
ignore, syslog, suspend, rotate
space_left Low water mark
space_left_action What action to take when low
water mark is reached
ignore, syslog, suspend, single,
halt
admin_space_left High water mark
admin_space_left_actio
n
What action to take when high
water mark is reached
ignore, syslog, suspend, single,
halt
disk_full_action What action to take when disk
is full
ignore, syslog, suspend, single,
halt
disk_error_action What action to take when an
error is encountered while
writing to disk.
Table 5-2: /etc/auditd.conf options
In addition to setting the audit filter rules, auditctl can be used to control the audit subsystem behavior in
the kernel even when auditd is running. These settings are listed in Table 5-3.
138
MENU

Models

Contents