audit: documentation of audit= kernel parameter
Further documentation of the 3 possible kernel value of the audit command line option. Signed-off-by: Eric Paris <eparis@redhat.com>
This commit is contained in:
parent
c81825dd6b
commit
d796114825
@ -465,6 +465,14 @@ bytes respectively. Such letter suffixes can also be entirely omitted.
|
||||
|
||||
audit= [KNL] Enable the audit sub-system
|
||||
Format: { "0" | "1" } (0 = disabled, 1 = enabled)
|
||||
0 - kernel audit is disabled and can not be enabled
|
||||
until the next reboot
|
||||
unset - kernel audit is initialized but disabled and
|
||||
will be fully enabled by the userspace auditd.
|
||||
1 - kernel audit is initialized and partially enabled,
|
||||
storing at most audit_backlog_limit messages in
|
||||
RAM until it is fully enabled by the userspace
|
||||
auditd.
|
||||
Default: unset
|
||||
|
||||
audit_backlog_limit= [KNL] Set the audit queue size limit.
|
||||
|
Loading…
Reference in New Issue
Block a user