Linux Operating System (MOSC)

MOSC Banner

Auditd Log Buffer exceeding - Will it cause slowness of OS/Database

We see the below messages are flooding the /var/log/messages on Physical servers running Greenplum Database and the message says the Audit buffer limit has exceeded. The Online documents suggests to increase buffer size and restart auditd service which is doable given these are physical servers with large RAM. Is there any standard calculation on buffer size to be set and Is it possible to track if these Audit messages flood is causing slowness of Database/Application and preventing DB to make system calls.

===============

kernel: audit: backlog limit exceeded

kernel: audit: audit_backlog=321 > audit_backlog_limit=320

==================

$ sudo aureport --start today --event --summary -i

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center