On Tue, Jan 04, 2005 at 03:08:34PM -0500, Steve Grubb wrote:
On Tuesday 04 January 2005 14:51, Stephen Smalley wrote:
> It belongs in an audit log, but you could certainly have multiple audit
> logs, with one dedicated to SELinux (i.e. MAC) audit messages.
One of the reasons I'm asking is because its not controlable via the audit
interface. Without any audit rules loaded, you get SE Linux audit messages
filling up the logs.
If you used laus, for example, does avc messages wind up in the logs?
No, LAuS doesn't interface to SELinux.
-Klaus