Is there any system performence penalty to enable auditing ?
Environment
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 5
Issue
- Is there any system
performencepenalty to enableauditing - Is there any alternatives to
auditto trace akiller, that have less impact on systemperformanceto tracekiller?
Resolution
- In order to
tracethe event before happening, the only way is setting theauditrule. - If using
64 bitsoftwares in the system, andkillis the onlysyscallthat iskillingyourprocessthen the correct rule should be:
# /sbin/auditctl -a exit,always -F arch=b64 -S kill -S tkill -S tgkill -F a1=10 -k signal10
- Adding a rule for both
32 bitand64 bitis likely to add overhead without any benefit consideringperformanceof the system. - If system is running both
32 bitand64 bitcompiledprocesses, addauditrule for both.
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
