Commit d7961148 authored by Eric Paris's avatar Eric Paris

audit: documentation of audit= kernel parameter

Further documentation of the 3 possible kernel value of the audit
command line option.
Signed-off-by: default avatarEric Paris <eparis@redhat.com>
parent c81825dd
...@@ -465,6 +465,14 @@ bytes respectively. Such letter suffixes can also be entirely omitted. ...@@ -465,6 +465,14 @@ bytes respectively. Such letter suffixes can also be entirely omitted.
audit= [KNL] Enable the audit sub-system audit= [KNL] Enable the audit sub-system
Format: { "0" | "1" } (0 = disabled, 1 = enabled) Format: { "0" | "1" } (0 = disabled, 1 = enabled)
0 - kernel audit is disabled and can not be enabled
until the next reboot
unset - kernel audit is initialized but disabled and
will be fully enabled by the userspace auditd.
1 - kernel audit is initialized and partially enabled,
storing at most audit_backlog_limit messages in
RAM until it is fully enabled by the userspace
auditd.
Default: unset Default: unset
audit_backlog_limit= [KNL] Set the audit queue size limit. audit_backlog_limit= [KNL] Set the audit queue size limit.
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment