audit_receive_filter — apply all rules to the specified message type
int audit_receive_filter ( | int type, |
| int pid, | |
| int uid, | |
| int seq, | |
| void * data, | |
| size_t datasz, | |
| uid_t loginuid, | |
| u32 sessionid, | |
u32 sid); |
typeaudit message type
pidtarget pid for netlink audit messages
uidtarget uid for netlink audit messages
seqnetlink audit message sequence (serial) number
datapayload data
dataszsize of payload data
loginuidloginuid of sender
sessionidsessionid for netlink audit message
sidSE Linux Security ID of sender