Audit subsystem not resolving path name on directory watches, resulting in name=(null)
Issue
Audit subsystem not resolving path name on directory watches, resulting in name=(null)
as seen here:
# ausearch --start recent | grep 'name=(null)'
type=PATH msg=audit(1454628867.199:29): item=1 name=(null) inode=298903 dev=fd:01 mode=0100644 ouid=0 ogid=0 rdev=00:00 obj=unconfined_u:object_r:admin_home_t:s0 nametype=NORMAL
Environment
- Red Hat Enterprise Linux 6.5
- kernel-2.6.32-431.el6 (or later)
- Red Hat Enterprise Linux 7
- kernel prior to kernel-3.10.0-229.4.2.el7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.