12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

508CHAPTER 25<strong>Linux</strong> Auditing Systemmax_log_fileMaximum log file size, in megabytes. When this size is reached, the action specifiedwith max_log_file_action is taken.max_log_file_actionspace_leftAction to take when the log file size from max_log_file is reached. Value must beone of IGNORE, SYSLOG, SUSPEND, ROTATE, and KEEP_LOGS. If set to IGNORE, noaction is taken after the log file size reaches max_log_file. If set to SYSLOG, awarning is written to the system log /var/log/messages after the file size isreached. If set to SUSPEND, audit messages aren’t written to the log file after thefile size is reached. If set to ROTATE, the log file is rotated after reaching the specifiedfile size, but only a certain number of old log files are saved as set by thenum_logs parameter. The old log files will have the filename audit.log.N, whereN is a number. The larger the number, the older the log file. If set to KEEP_LOGS,the log file is rotated, but the num_logs parameter is ignored so that no log filesare deleted.Amount of free disk space in megabytes. When this level is reached, the actionfrom the space_left_action parameter is taken.space_left_actionWhen the amount of free disk space reaches the value from space_left, thisaction is taken. Valid values are IGNORE, SYSLOG, EMAIL, SUSPEND, SINGLE, andHALT. If set to IGNORE, no action is taken. If set to SYSLOG, a warning message iswritten to the system log /var/log/messages. If set to EMAIL, an email is sent tothe address from action_mail_acct, and a warning message is written to/var/log/messages. If set to SUSPEND, no more log messages are written to theaudit log file. If set to SINGLE, the system is put in single user mode. If set toHALT, the system is shut down.action_mail_acctEmail address of the administrator responsible for maintaining the audit daemonand logs. If the address does not have a hostname, it is assumed the address islocal such as root. sendmail must be installed and configured to send email tothe specified email address.admin_space_leftAmount of free disk space in megabytes. Use this option to set a more aggressiveaction than space_left_action in case the space_left_action does not causethe administrator to free any disk space. This value should be lower thanspace_left_action. If this level is reached, the action fromadmin_space_left_action is taken.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!