Hello,
On Tuesday, November 30, 2021 6:04:28 PM EST Amjad Gabbar wrote:
I am currently seeing a lot of auditd dispatch error issues.
What version of auditd and what plugins do you have?
It is related to a particular keyed rule that from the looks of it
is
generating close to a million events /day. I have seen previous answers
where it was advised to increase the q_depth value to a suitable number.
Based on this, I would like to confirm what is the maximum advisable value
q_depth can have/take?
Depends on what you are willing to set it to. You can easily go to 64k, but
you really ought to look at the plugins to see why they can't keep up. And of
course, are the rules really designed right and you need the million events/
day?
-Steve