execve、execveat 監査ルールが原因の高負荷と遅延
Issue
-
execve
、execveat
監査ルールが原因で、高負荷と遅延が発生します。Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338144 audit_rate_limit=0 audit_backlog_limit=10240
Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow
Jan 5 12:52:43 Hostname kernel: audit: type=1307 audit(1672944760.823:772292147): cwd="program/command/file"
Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338145 audit_rate_limit=0 audit_backlog_limit=10240
Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow
Jan 5 12:52:44 Hostname auditd[1484]: Error receiving audit netlink packet (No buffer space available)
Environment
- Red Hat Enterprise Linux 8
- 監査ルール
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.