[CentOS] selinux...

Wed Oct 7 18:09:19 UTC 2009
nate <centos at linuxpowered.net>

m.roth at 5-cent.us wrote:

> You begin to see my frustration, esp. when I have to skim through logs
> that have a dozen, or two dozen, of these (and others) every hour, to find
> other more important messages.

How about log filtering? Since your in such a high security
environment to need SELinux I can't imagine you don't have
some sort of log management tool such as Splunk or something
similar. I'm still in the midst of a Splunk deployment and
have it stripping a bunch of useless stuff out of the logs,
also have syslog-ng dropping a ton of useless crap as well.

I used to manage a pair of Siteminder systems several years
ago, your email got me curious and I poked around to see if
they were still alive, and yes they are and still running
the good 'ol Apache 1.3.27 probably on RHEL 2.1 still!
Funny they haven't upgraded it, it's not like they process
credit cards or anything, oh wait..they do. oh well! Not
my problem:)

nate