|
I'm using the standard auditd in Linux to capture "permission denied" messages. For some odd reason, auditd likes to store usernames as numbers (eg |
|
You should check out the Unfortunately, the default http://answers.splunk.com/questions/5650/nix-possible-bug-in-rlog-sh-script/5725#5725 |