/var/log/messages 中的 'kernel: audit: backlog limit exceeded' 消息
Issue
-
/var/log/messages显示重复消息,表示audit_backlog大于允许的限制kernel: audit: audit_backlog=65537 > audit_backlog_limit=65536 kernel: audit: audit_lost=126533574 audit_rate_limit=0 audit_backlog_limit=65536
Environment
- Red Hat Enterprise Linux (RHEL)
- auditd
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.