The auditd daemon stops logging after deleting audit.log until auditd is restarted
I am using Red Hat Enterprise Linux Server 6.1 and must copy audit.log files on a weekly basis to DVD and save them off on another audit log backup server. After clearing (deleting using rm -Rf) audit.log files and without restarting the auditd daemon, I noticed the server doesn't log any more events until I restart the auditd daemon (by rebooting). Is this typical of auditd to stop logging once audit.log has been deleted, requiring the daemon to be restarted?
|