AUDIT_SET_BACKLOG_LIMIT(3)brary Functions ManualDIT_SET_BACKLOG_LIMIT(3)
audit_set_backlog_limit - Set the audit backlog limit
#include <libaudit.h> int audit_set_backlog_limit(int fd, uint32_t limit);
audit_set_backlog_limit sets the queue length for audit events awaiting transfer to the audit daemon. The default value is 64 which can potentially be overrun by bursts of activity. When the backlog limit is reached, the kernel consults the failure_flag to see what action to take.
The return value is <= 0 on error, otherwise it is the netlink sequence id number. This function can have any error that sendto would encounter.
audit_set_failure(3), audit_open(3), auditd(8), auditctl(8).
This page is part of the audit (Linux Audit) project. Information about the project can be found at ⟨http://people.redhat.com/sgrubb/audit/⟩. If you have a bug report for this manual page, send it to email@example.com. This page was obtained from the project's upstream Git repository ⟨https://github.com/linux-audit/audit-userspace.git⟩ on 2021-08-27. (At that time, the date of the most recent commit that was found in the repository was 2021-08-21.) If you discover any rendering problems in this HTML version of the page, or you believe there is a better or more up-to-date source for the page, or you have corrections or improvements to the information in this COLOPHON (which is not part of the original manual page), send a mail to firstname.lastname@example.org Linux Audit API Oct 2006 AUDIT_SET_BACKLOG_LIMIT(3)
Pages that refer to this page: audit_set_backlog_wait_time(3), audit_set_failure(3)