audit_set_backlog_limit — Set the audit backlog limit


#include <libaudit.h>

int audit_set_backlog_limit (int fd, int limit);


audit_set_backlog_limit sets the queue length for audit events awaiting transfer to the audit daemon. The default value is 64 which can potentially be overrun by bursts of activity. When the backlog limit is reached, the kernel consults the failure_flag to see what action to take.

Return Value

The return value is <= 0 on error, otherwise it is the netlink sequence id number. This function can have any error that sendto would encounter.

See Also

audit_set_failure(3), audit_open(3), auditd(8), auditctl(8).


Steve Grubb

Referenced By


Oct 2006 Linux Audit API