Hi Steve, everyone,
I was playing with auditd and aushape on Fedora 24 and found some strange
entries in my log. There was a separate *event* produced by auparse containing
a single EOE record. These events had the same serial number as the directly
preceding events, which were exclusively containing SYSCALL records.
Those EOE records didn't appear in the audit.log file.
Is this a bug? Is this normal?
Thank you.
Nick