如何修复auditd日志报错问题?
- By : Will
- Category : FTP & SFTP & FTPS

FTP & SFTP & FTPS
1 前言
一个问题,一篇文章,一出故事。
今天遇到sftp的audit日志没有记录问题,通过如下命令查看服务,
systemctl status auditd
可见如下错误,
Sep 25 14:06:33 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:34 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:34 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:35 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:40 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:40 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available) Sep 25 14:06:40 sftp.cmdschool.org auditd[719779]: Error receiving audit netlink packet (No buffer space available)
2 最佳实践
2.1 修改审计缓冲区大小
vim /etc/audit/rules.d/audit.rules
修改如下参数,
-b 32768
注:修改的值应该大于32768
2.2 重启服务器使服务生效
reboot
没有评论