Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

I tried to start a second eXpert-BSM monitor on the same machine, but it did not work. Why?

expert-bsm Machine monitor
0
Posted

I tried to start a second eXpert-BSM monitor on the same machine, but it did not work. Why?

0

Running more than one eXpert-BSM monitor on the same machine will not work in real-time mode because only one process can record audit records from the kernel. That is also the reason why auditd cannot coexist with ebsmprobe. For batch mode, you can run several eXpert-BSM monitors in parallell as long as you are careful about not clearing a results directory that another monitor is writing to.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123