On Thursday 14 August 2008 19:50:23 LC Bruzenak wrote:
> I cannot speak for other end-users...but my guess is that if they are
> using audit and aggregating they probably care about not dropping it,
> whereas others can just syslog the events if the auditd isn't enabled
> and then use centralized syslog, right?

Does syslog queue unsent messages and recover them?

-Steve

--
Linux-audit mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/linux-audit

Reply via email to