Score:0

Troubleshooting auditd rules

cn flag

I'm running RHEL 7.x. We have recently installed the DISA recommended rules for auditd.

Since we've installed these new audit rules, we've noticed a significant decrease in system performance.
Ex:
rsyncing the 117Mb firefox files to /dev/shm took 32 seconds. Deleting took 28 seconds.
Deleting should take 0.02 seconds!

We've found 1 or 2 CPUs are pegged at near 100% usage for auditd. Waiting for I/O is consistently in the 5-8% range.

Our build servers should build in 45-60min. Now they take all night and time-out.

Question:
How can I troubleshoot the rules to determine which ones are causing the biggest load on the system?

TIA

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.