On Thursday 14 August 2008 19:50:23 LC Bruzenak wrote: > I cannot speak for other end-users...but my guess is that if they are > using audit and aggregating they probably care about not dropping it, > whereas others can just syslog the events if the auditd isn't enabled > and then use centralized syslog, right?
Does syslog queue unsent messages and recover them? -Steve -- Linux-audit mailing list [email protected] https://www.redhat.com/mailman/listinfo/linux-audit
