配置auditd的num_logs值为5,但是发现并不生效,初始配置大概是这样
log_file = /xxx/xxx.log
log_format = RAW
log_group = root
priority_boost = 4
flush = INCREMENTAL
freq = 20
num_logs = 5
disp_qos = lossy
dispatcher = /sbin/audispd
name_format = NONE
##name = mydomain
max_log_file = 6
max_log_file_action = ROTATE
space_left = 75
space_left_action = SYSLOG
......
后来心想日志保留文件数跟ROTATE是有关联的,抱着试试的态度将num_logs 放到max_log_file_action后面,发现果然生效了,这里记录下留作备忘