Hi,
The 30-pci-dss-v31.rules in the doc directory contains the following statement :
## 10.2.6 Verify the following are logged:
## Initialization of audit logs
## Stopping or pausing of audit logs.
## These are handled implicitly by auditd
This very good since nothing need to be done, but how can I actually find when these events occur ?
I am not sure what means “pausing of audit logs”, can we really “pause” auditd ?
Philippe