packetzero
02/08/2019, 2:50 PMshed7
02/08/2019, 2:56 PMpacketzero
02/08/2019, 2:57 PMshed7
02/08/2019, 2:58 PMpacketzero
02/08/2019, 2:58 PMshed7
02/08/2019, 2:59 PMpacketzero
02/08/2019, 2:59 PMshed7
02/08/2019, 3:01 PM--audit_force_reconfigure=true
--audit_debug
--logger_min_status=1
--disable_events=false
--logger_plugin=syslog
--host_identifier=hostname
--schedule_splay_percent=10
--disable_audit=false
--audit_allow_config=true
--audit_persist=true
--audit_allow_process_events=true
--events_expiry=120
--events_max=50000
--audit_allow_sockets=true
--verbose
--watchdog_delay=120
--disable_extensions=true
"file_events": {
"query": "SELECT * from file_events;",
"removed": false,
"interval": 30
"socket_events":{
"query": "SELECT s.action, s.auid, s.family, s.local_address, s.local_port, s.path, s.pid, s.remote_address, s.remote_port, s.success, s.time, p.cmdline, p.cmdline_size, p.parent, p.uid, p.euid FROM socket_events s JOIN process_events p ON p.pid = s.pid WHERE s.action='bind';",
"removed": false,
"interval": 60
},
"process_events": {
"query": "SELECT auid, cmdline, ctime, cwd, egid, euid, gid, parent, path, pid, time, uid FROM process_events WHERE path NOT IN ('/bin/date', '/bin/mktemp', '/usr/bin/dirname', '/usr/bin/head', '/bin/uname', '/bin/basename');",
"removed": false,
"interval": 30
packetzero
02/08/2019, 3:09 PMshed7
02/08/2019, 3:14 PMpacketzero
02/08/2019, 3:15 PMshed7
02/08/2019, 4:43 PMdata.auditeventpublisher.process_events.0003350252' seq:6482196, type:0 =>
packetzero
02/09/2019, 7:43 PM钢铁侠
02/11/2019, 3:42 AMIndexes are only being deleted if all queries have been completed. But I don't think the query results are posted yethow can we avoid this?
packetzero
02/11/2019, 4:54 AM钢铁侠
02/11/2019, 5:00 AMpacketzero
02/11/2019, 5:15 AM钢铁侠
02/11/2019, 5:22 AMpacketzero
02/11/2019, 5:46 AM钢铁侠
02/11/2019, 5:56 AMcurl
. it seems that the machine does not record the process_events. but the status of audit is normal.RocksDB: [WARN] [db/column_family.cc:675] [queries] Stalling writes because we have 15 immutable memtables .....
shed7
02/11/2019, 2:36 PM钢铁侠
02/12/2019, 5:08 AMshed7
02/12/2019, 8:42 AM钢铁侠
02/13/2019, 8:13 AMshed7
02/13/2019, 8:32 AMpacketzero
02/13/2019, 2:37 PMshed7
02/13/2019, 3:24 PM