We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 3a56901 commit 65b278fCopy full SHA for 65b278f
1 file changed
linux_os/guide/auditing/auditd_configure_rules/audit_rules_mac_modification_var_lib_selinux/rule.yml
@@ -4,6 +4,8 @@ title: 'Record Events that Modify the System''s Mandatory Access Controls in /va
4
5
description: |-
6
{{{ describe_audit_rules_watch("/var/lib/selinux/", "MAC-policy") }}}
7
+ Note that monitoring /var/lib/selinux/ will generate a significant burst of audit events
8
+ during both selinux-policy* package upgrade and policy rebuild.
9
10
rationale: |-
11
The system's mandatory access policy (SELinux) should not be
0 commit comments