audit_set_backlog_limit(3) — Linux manual page


AUDIT_SE...LOG_LIMIT(3) Library Functions Manual AUDIT_SE...LOG_LIMIT(3)

NAME         top

       audit_set_backlog_limit - Set the audit backlog limit

SYNOPSIS         top

       #include <libaudit.h>

       int audit_set_backlog_limit(int fd, uint32_t limit);

DESCRIPTION         top

       audit_set_backlog_limit sets the queue length for audit events
       awaiting transfer to the audit daemon. The default value is 64
       which can potentially be overrun by bursts of activity. When the
       backlog limit is reached, the kernel consults the failure_flag to
       see what action to take.

RETURN VALUE         top

       The return value is <= 0 on error, otherwise it is the netlink
       sequence id number. This function can have any error that sendto
       would encounter.

SEE ALSO         top

       audit_set_failure(3), audit_open(3), auditd(8), auditctl(8).

AUTHOR         top

       Steve Grubb

COLOPHON         top

       This page is part of the audit (Linux Audit) project.
       Information about the project can be found at 
       ⟨⟩.  If you have a bug
       report for this manual page, send it to
       This page was obtained from the project's upstream Git repository
       ⟨⟩ on
       2023-12-22.  (At that time, the date of the most recent commit
       that was found in the repository was 2023-11-30.)  If you
       discover any rendering problems in this HTML version of the page,
       or you believe there is a better or more up-to-date source for
       the page, or you have corrections or improvements to the
       information in this COLOPHON (which is not part of the original
       manual page), send a mail to

Linux Audit API                 Oct 2006         AUDIT_SE...LOG_LIMIT(3)

Pages that refer to this page: audit_set_backlog_wait_time(3)audit_set_failure(3)