audit_set_backlog_limit(3) — Linux manual page
AUDIT_SE...LOG_LIMIT(3) Library Functions Manual AUDIT_SE...LOG_LIMIT(3)
NAME
audit_set_backlog_limit - Set the audit backlog limit
SYNOPSIS
#include <libaudit.h>
int audit_set_backlog_limit(int fd, uint32_t limit);
DESCRIPTION
audit_set_backlog_limit sets the queue length for audit events
awaiting transfer to the audit daemon. The default value is 64
which can potentially be overrun by bursts of activity. When the
backlog limit is reached, the kernel consults the failure_flag to
see what action to take.
RETURN VALUE
The return value is <= 0 on error, otherwise it is the netlink
sequence id number. This function can have any error that sendto
would encounter.
SEE ALSO
audit_set_failure(3), audit_open(3), auditd(8), auditctl(8).
AUTHOR
Steve Grubb
COLOPHON
This page is part of the audit (Linux Audit) project.
Information about the project can be found at
⟨http://people.redhat.com/sgrubb/audit/⟩. If you have a bug
report for this manual page, send it to linux-audit@redhat.com.
This page was obtained from the project's upstream Git repository
⟨https://github.com/linux-audit/audit-userspace.git⟩ on
2024-06-14. (At that time, the date of the most recent commit
that was found in the repository was 2024-06-12.) If you
discover any rendering problems in this HTML version of the page,
or you believe there is a better or more up-to-date source for
the page, or you have corrections or improvements to the
information in this COLOPHON (which is not part of the original
manual page), send a mail to man-pages@man7.org
Linux Audit API Oct 2006 AUDIT_SE...LOG_LIMIT(3)
Pages that refer to this page: audit_set_backlog_wait_time(3), audit_set_failure(3)