High load and slowness due to execve, execveat audit rules
Issue
-
High load and slowness due to
execve,execveataudit rules.Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338144 audit_rate_limit=0 audit_backlog_limit=10240 Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow Jan 5 12:52:43 Hostname kernel: audit: type=1307 audit(1672944760.823:772292147): cwd="program/command/file" Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338145 audit_rate_limit=0 audit_backlog_limit=10240 Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow Jan 5 12:52:44 Hostname auditd[1484]: Error receiving audit netlink packet (No buffer space available)
Environment
- Red Hat Enterprise Linux 8
- Audit Rules
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.