Skip to content

Auditd collector drops events when monitoring setuid/setgid activity on Docker Swarm nodes #2783

Description

@securemeit

Acknowledgements

Describe the bug

Environment

UTMStack Agent: 11.1.4
OS: Ubuntu Linux
Kernel: 6.8.0-142-generic
auditctl: 3.1.2
Docker Swarm environment

Issue

When the audit rule utmstack_priv is enabled:

-a always,exit -F arch=b64 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv
-a always,exit -F arch=b32 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv

the agent logs:

auditd: queue full, dropping event

Kernel audit status shows:

lost 0

so the drops happen inside the UTMStack agent collector.

Evidence

ausearch -k utmstack_priv shows mainly:

comm="runc:[2:INIT]"
exe="/runc"

Executable summary:

82 /runc

Removing only the utmstack_priv rule stops the queue full errors immediately.

All other audit rules continue working normally.

Expected behavior

The agent should handle high-volume audit events without dropping messages, or provide a way to filter noisy container runtime events.

Question

Is this a known limitation of the auditd collector?
Should Docker/runc generated privilege-change events be filtered by default?

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

No queue full

Current Behavior

queue full

Reproduction Steps

See description of bug

Possible Solution

No response

Additional Information/Context

No response

UTMStack Version

11.2.14

Operating System and version

Ubuntu 24.04.5 LTS

Hypervisor and Version | Server Vendor and Model

not needed

Browser and version

not needed

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions