[19:16] <sadmac2> Keybuk: did you see the audit patch on upstart devel list?
[19:17] <Keybuk> I've seen it before
[19:17] <Keybuk> I assume that it is the same one
[19:17] <sadmac2> Keybuk: I don't know, could be.
[19:17] <sadmac2> Keybuk: the guy who wrote it wants us to roll it into our rpms. What's your opinion of the patch itself?
[19:18] <Keybuk> without knowing what audit does, it's hard to say
[19:18] <sadmac2> Keybuk: fancy logging.
[19:19] <sadmac2> notting: you can elaborate if you like. I'm not much of an expert either.
[19:20] <notting> kernel-based audit trail of events
[19:20] <notting> less forgeable than syslog, i suppose
[19:20] <sadmac2> so syslog for security crazies
[19:21] <sadmac2> (not to be mean, I love those guys)
[19:22] <notting> structured syslog
[19:22] <notting> (defined events, defined fields, etc.)
[19:23] <sadmac2> that's nice