Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFE: add support action "exec" for max_log_file_action similar space_left_action action "exec" #220

Open
GYShit opened this issue Oct 13, 2021 · 1 comment
Labels

Comments

@GYShit
Copy link

GYShit commented Oct 13, 2021

Add support action "exec" for max_log_file_action similar space_left_action action "exec". Then There will be more powerful extended processing capabilities

Currently max_log_file_action in auditd.conf has valid values below:
“ignore ", " syslog ", " suspend ", " rotate " and "keep_logs.

Comparing space_left_action and admin_space_left_action, there is no custom action “exec”

@stevegrubb
Copy link
Member

The only issue with this is that auditd would have to close the logging descriptor and suspend logging. That means whatever gets executed will need to send SIGUSR2 to it's ppid to restart logging.

@stevegrubb stevegrubb added the RFC label Aug 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants