How to recover error - Audit error: dispatch err (pipe full) event lost

How to recover error - Audit error: dispatch err (pipe full) event lost?

Solution Unverified - Updated -

Environment

  • Red Hat Enterprise Linux 7.3

Issue

  • Log file /var/log/messages showing audit error as below -

    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch err (pipe full) event lost
    dispatch error reporting limit reached - ending report notification.
    

Resolution

  • Edit /etc/audit/auditd.conf and set the value of disp_qos=lossy setting to disp_qos=lossless

    cat /etc/audit/auditd.conf  | grep disp_qos
    disp_qos=lossless 
    

Root Cause

  • The reason behind this error is that program is not pulling the events from the audit daemon fast enough.
0 (0)
Article Rating (No Votes)
Rate this article
Attachments
There are no attachments for this article.
Comments
There are no comments for this article. Be the first to post a comment.
Full Name
Email Address
Security Code Security Code
Related Articles RSS Feed
CONFIGURE OCFS2
Viewed 1760 times since Sat, Jun 2, 2018
RHEL: Crash kernel dumps configuration and analysis on RHEL 6
Viewed 1200 times since Sat, Jun 2, 2018
Check a Website Availability from the Linux Command Line
Viewed 437 times since Mon, Feb 18, 2019
Using Official Redhat DVD as repository
Viewed 719 times since Mon, Oct 29, 2018
OpenSSL: Find Out SSL Key Length – Linux Command Line
Viewed 430 times since Mon, Feb 18, 2019
Migrate a Linux System from Red Hat Enterprise to CentOS
Viewed 81 times since Fri, May 15, 2020
RHEL: Extending the maximum inode count on a ext2/ext3/ext4 filesystem
Viewed 969 times since Sun, May 27, 2018
20 IPtables Examples For New SysAdmins
Viewed 332 times since Fri, May 15, 2020
Learn how to align an SSD on Linux
Viewed 104 times since Fri, May 15, 2020
Top 4 Reasons for Node Reboot or Node Eviction in Real Application Cluster (RAC) Environment
Viewed 7464 times since Thu, Jun 21, 2018