Skip to content

Commit 65b278f

Browse files
committed
add a warning about a large log volume
1 parent 3a56901 commit 65b278f

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

  • linux_os/guide/auditing/auditd_configure_rules/audit_rules_mac_modification_var_lib_selinux

linux_os/guide/auditing/auditd_configure_rules/audit_rules_mac_modification_var_lib_selinux/rule.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,8 @@ title: 'Record Events that Modify the System''s Mandatory Access Controls in /va
44

55
description: |-
66
{{{ describe_audit_rules_watch("/var/lib/selinux/", "MAC-policy") }}}
7+
Note that monitoring /var/lib/selinux/ will generate a significant burst of audit events
8+
during both selinux-policy* package upgrade and policy rebuild.
79
810
rationale: |-
911
The system's mandatory access policy (SELinux) should not be

0 commit comments

Comments
 (0)