auditd rule "-F auid>=500" produces "missing operation for auid" error.
Issue
-
Why does "-F auid>=500" from the audit rules produce the "error -F missing operation for auid"?
-
auditd rules not being sent to syslog.
Environment
- Red Hat Enterprise Linux
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.