Share

SNARE - Auditing and EventLog Management

The forum address has changed, you have been automatically redirected. Please update any bookmarks to use the new URL.

Subscribe

Why kernel patching and not modkaf on RH 4?

You are viewing a single message from this topic. View all messages.

  1. 2005-12-01 19:56:32 UTC
    I'm using Snare Agent for Windows with great results, but Kernel patching RedHat Enterpise 4 kernels is just not an option as you lose RH tech support plus other 'corporate' issues.

    I'm looking at auditd on RH 4, and that comes with CAPP rules. That just uses a kernel module (modkaf) instead of kernel patches (which it used to use, and has now moved away from).

    Why doesn't Snare use the same facility for the same results?
< Previous | 1 | Next >

Add a Reply

This forum does not allow anonymous participation.

Log in to add a reply. Not registered? Create an account to participate and receive email updates when replies are posted to this topic.