OL7 & 8: Why /etc/audit/audit.rules Files are Overwritten After auditd Service Restart
(Doc ID 2859136.1)
Last updated on MARCH 30, 2022
Applies to:Oracle Cloud Infrastructure - Version N/A and later
Linux OS - Version Oracle Linux 7.0 and later
This document explains why /etc/audit/audit.rules are overwritten after restarting auditd service and the steps to disable the augenrules utility, so that Audit will use rules defined in the /etc/audit/audit.rules file.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document