audit_set_backlog_limit — Set the audit backlog limit

Synopsis

#include <libaudit.h>

int audit_set_backlog_limit (int fd, int limit);

Description

audit_set_backlog_limit sets the queue length for audit events awaiting transfer to the audit daemon. The default value is 64 which can potentially be overrun by bursts of activity. When the backlog limit is reached, the kernel consults the failure_flag to see what action to take.

Return Value

The return value is <= 0 on error, otherwise it is the netlink sequence id number. This function can have any error that sendto would encounter.

See Also

audit_set_failure(3), audit_open(3), auditd(8), auditctl(8).

Author

Steve Grubb

Referenced By

audit_set_backlog_wait_time(3).

Oct 2006 Linux Audit API