Files
alexpolo1 a3b8959ca9 Initial collection structure
Migrated from legacy playbook repo into Ansible collection format:

Roles (171 total):
- common: 44 roles (fact gathering, SSH setup, utilities)
- configuration: 32 roles (system config, networking, satellite)
- provisioning: 16 roles (VMware, Azure, physical server deployment)
- security: 15 roles (OpenSCAP hardening, certificates, AD integration)
- monitoring: 12 roles (Zabbix, logging agents, metrics)
- networking: 12 roles (DNS, DHCP, network interfaces)
- satellite: 4 roles (Pulp/Satellite management)
- misc: 36 roles (various utilities)

Playbooks (159 total):
- provisioning: 14 playbooks
- azure: 13 playbooks
- configuration: 22 playbooks
- maintenance: 10 playbooks
- security: 10 playbooks
- monitoring: 9 playbooks
- vcenter: 6 playbooks
- networking: 7 playbooks
- misc: 65 playbooks
2026-06-27 21:48:22 +02:00

1.1 KiB

fix--audit-logs-in-message

Configure whether auditd should send events to syslog or not.

Default is not, since auditd's own native logging to disk (/var/log/audit/) should suffice.

Sending auditd events to syslog will cause "logging storms" if auditd is monitoring rsyslog. Which is currently the case when mdatp (Microsoft Defender) has also been installed on the target.

Role Variables

See defaults/main.yml.

Example Playbook

Enable auditd send events to syslog (default is "no"):

- hosts: servers
  roles:
     - role: fix--audit-logs-in-message
       vars: auditd_syslog_active: "yes"

OS version support

  • RHEL 7
  • RHEL 8

Todo