Figure 5-69: Audit framework components
5.6.1.1Audit kernel components
Linux Audit of the SLES kernel includes three
5.6.1.1.1Kernel-userspace interface
On top of netlink, there exists the generic netlink family that provides simplified access for less demanding users. This introduces a control for ID management and name resolution, and possesses a new type of safety interface for netlink messages and attributes handling. This interface also features simplified message constructing, validation capabilities, and documentation.
This first component also receives
132