Hello Dave,
This seems like unexpected behavior, especially the part where you need to disable/re-enable FAL to see the records.To answer your question
Is it intended for the audit mechanism to be a soft audit? i.e the
audit is best effort, and non blocking for file access.
>>> file audit
Hello
I am currently testing out the FAL and watch folders auditing mechanism in
5.1.0. I have noticed that audit events such as file access or creation
are not always recorded in the FAL log on the filesystem. It would seem
necessary to disable and re enable FAL auditing for the same file