Select Your Language

Infrastructure and Management

Cloud Computing

Storage

Runtimes

Integration and Automation

  • Comments
  • Help on audit.log

    Posted on

    Dear Team,

    I need a help on understanding the audit.log file on Linux servers.
    I can see the audit logs under /var/log/audit/ folder and a configuration file for that in /etc/audit/auditd.conf

    What actually getting recorded in audit.old file, Is the same information in /var/log/secure and other log files.
    What is the distinct feature of this log file.

    The reason for bringing up this question is we have a concern audit log message getting filled up and hungs the servers with the below message.

    kernel: audit: audit_backlog=65537 > audit_backlog_limit=65536
    kernel: audit: audit_lost=126533574 audit_rate_limit=0 audit_backlog_limit=65536

    So is that really audit.log is nescessary or Can I stop the auditd process and get the details from other logs like messages/secure.

    Please help, Thanks.

    by

    points

    Responses

    Red Hat LinkedIn YouTube Facebook X, formerly Twitter

    Quick Links

    Help

    Site Info

    Related Sites

    © 2026 Red Hat