I think the auditd package that ships with 5.3 has a bug. Use one of the newer versions available from
http://people.redhat.com/sgrubb/audit/index.html
On Mon, 2009-04-27 at 11:15 -1000, Dave Trepanier wrote:
uditd audit.log files stops receiving log entries until the auditd service is stopped and restarted. The logs entries re-start also after I run audit –f. I have been thinking about updating auditd , currently release 7.7.7-6, to a newer release. The challenge is updating it without an internet connection. The machine cannot be connected to the internet, so all program dependencies need to be installed manually. Does anyone k