You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Linux auditd报错“Error receiving audit netlink packet (No buffer space available)”的事件影响咨询

Hey there, let’s cut straight to the chase since you already know how to tweak the buffer settings—here’s the concrete impact you’re asking about:

  • Yes, you are absolutely losing audit events when this error pops up. Let me break down why:
    auditd pulls audit events from the kernel via the netlink interface. The kernel maintains a buffer for these events waiting to be sent to auditd. Once this buffer hits its limit, the kernel has no space to store new incoming events, so it drops them entirely. This error message is the kernel’s direct alert that this overflow is happening.

  • Those lost events are permanently gone—the kernel won’t queue them up to send later once space frees up. They never make it to auditd, which means they’ll never show up in your audit logs. (Quick note: I think you might have a typo with "in the blog"—I assume you meant "in the log"! 😊)

  • To confirm you’ve lost events, you can check the kernel’s built-in counter with this command:

    cat /proc/sys/kernel/audit/lost
    

    If the number returned is greater than 0, that’s hard proof that audit events have been discarded due to buffer shortages.

This issue typically crops up when your audit rules generate events faster than auditd can process and write them to disk, or when the default buffer size is too small for your server’s workload. Since you already know how to adjust the audit.rules buffer settings, fixing that should put a stop to the event loss.

备注:内容来源于stack exchange,提问作者Egyas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 15:39:35