auditd is logging to /var/log/messages
Hello,
We do sometimes experience that auditd begins to log to /var/log/messages instead of /var/log/audit/audit.log in connection with a restart of the service, despite it's defined in auditd config that it should log to last mentioned file.
This happens randomly (and rarely) on our +1.700 servers, even without changing anything other than only restarting the service.
Restarting the service once again fixes the problem.
We see this issue on both Oracle Linux 7 and 8 servers.
Can you help us explain and/or debug what causes this issue?
Best regards,
Kenny Lindberg