In short, my question is: my program depends on audispd to dispatch audit messages, for security's sake, when audispd is killed, how can I know it happened in time in order to restart audispd?
On Tuesday, January 05, 2016 06:08:54 PM Matthew Chao wrote:
> >"You can watch audispd, but I don't think that will help anything.
>
> my program totally depends on audispd to dispatch audit messages. I think
> audispd need more robust mechanisms to monitor itself killed, otherwise
> which inevitably leads to that audispd' plugins receive nothing but always
> wait wait wait for event messages.
>
> So are there some alternative ways to monitor audispd killed in audit
> ver1.8 ?
To help you, I need to know more about what the actual problem is that you are
trying to solve. Would you like to explain the problem so we can help figure
out how to address it?
Thanks,
-Steve