Auditd Log Buffer exceeding - Will it cause slowness of OS/Database
We see the below messages are flooding the /var/log/messages on Physical servers running Greenplum Database and the message says the Audit buffer limit has exceeded. The Online documents suggests to increase buffer size and restart auditd service which is doable given these are physical servers with large RAM. Is there any standard calculation on buffer size to be set and Is it possible to track if these Audit messages flood is causing slowness of Database/Application and preventing DB to make system calls.
===============
kernel: audit: backlog limit exceeded
kernel: audit: audit_backlog=321 > audit_backlog_limit=320
==================
$ sudo aureport --start today --event --summary -i