由于 execve, execveat 审计规则导致高负载和运行缓慢
Issue
- 
由于
execve、execveat审计规则导致高负载和运行缓慢。Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338144 audit_rate_limit=0 audit_backlog_limit=10240 Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow Jan 5 12:52:43 Hostname kernel: audit: type=1307 audit(1672944760.823:772292147): cwd="program/command/file" Jan 5 12:52:43 Hostname kernel: audit: audit_lost=1279338145 audit_rate_limit=0 audit_backlog_limit=10240 Jan 5 12:52:43 Hostname kernel: audit: kauditd hold queue overflow Jan 5 12:52:44 Hostname auditd[1484]: Error receiving audit netlink packet (No buffer space available) 
Environment
- Red Hat Enterprise Linux 8
- 审计规则
 
 
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.