DJ (or anyone) -
Is there a HOWTO for activating the 1.7.5 aggregating feature?
My apologies if I missed this earlier.
I believe that the collector needs to uncomment the lines
in /etc/auditd/auditd.conf and the senders/clients need to set
active=yes, remote=<IP-address> in the audisp-remote.conf file.
However, my collector auditd fails on start; it might be that I do not
have it configured correctly.
I have : audit-1.7.5-1.fc9.i386
Thx,
LCB.
--
LC (Lenny) Bruzenak
lenny(a)magitekltd.com