Why audit daemon logging ntp events continously after adding audit rule for system time change
Issue
Audit daemon logging ntp events as below continously after adding audit rule for system time change log numerous ntp audit messages in audit log file as below:
node:mywkstn type SYSCALL msg=audit(1362565803.004:606216): arch-c000003e syscall=159 success=yes exit=5 a0=7ff58ac9540 a1=0 a2=0 a3=0 items=0 ppid=1 pid=15839 auid=2028 uid=38 euid=38 suid=38 fsuid=38 egid=38 sgid=38 fsgid=38 tty=(none) ses=891 comm="ntpd" exe="/sbin/ntpd" key="time-change"
audit.rules contains:
-a entry,always -F arch=b64 -S adjtimex -S clock_settime -S settimeofday -k time-change
Environment
- Red Hat Enterprise Linux 5
- ntp-4.2.2p1-15.el5_7.1
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
