Hello,
I've discovered another situation where audit is still auditing
itself. When I have audit enabled but I'm not running the daemon, and
add rules like:
# auditctl -a entry,always -S open
# auditctl -a entry,always -S close
Doing something like 'auditctl -l' floods the console with audit
records.
Has anyone else seen this? I'm running the .81 kernel.
Thanks,
Amy