On Thursday, November 25, 2010 03:06:16 am Peng Haitao wrote: > Use option '--session Login-Session-ID' cannot search out the log which > contains the given Login Session ID and message type is MAC_POLICY_LOAD. > > For example: > # echo "type=MAC_POLICY_LOAD msg=audit(1290670949.711:413341): policy > loaded auid=0 ses=218" | ausearch --session 218 <no matches> > > Signed-off-by: Peng Haitao <[email protected]>
Applied. Thanks, -Steve -- Linux-audit mailing list [email protected] https://www.redhat.com/mailman/listinfo/linux-audit
