Acknowledgements
Describe the bug
Environment
UTMStack Agent: 11.1.4
OS: Ubuntu Linux
Kernel: 6.8.0-142-generic
auditctl: 3.1.2
Docker Swarm environment
Issue
When the audit rule utmstack_priv is enabled:
-a always,exit -F arch=b64 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv
-a always,exit -F arch=b32 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv
the agent logs:
auditd: queue full, dropping event
Kernel audit status shows:
lost 0
so the drops happen inside the UTMStack agent collector.
Evidence
ausearch -k utmstack_priv shows mainly:
comm="runc:[2:INIT]"
exe="/runc"
Executable summary:
82 /runc
Removing only the utmstack_priv rule stops the queue full errors immediately.
All other audit rules continue working normally.
Expected behavior
The agent should handle high-volume audit events without dropping messages, or provide a way to filter noisy container runtime events.
Question
Is this a known limitation of the auditd collector?
Should Docker/runc generated privilege-change events be filtered by default?
Regression Issue
Expected Behavior
No queue full
Current Behavior
queue full
Reproduction Steps
See description of bug
Possible Solution
No response
Additional Information/Context
No response
UTMStack Version
11.2.14
Operating System and version
Ubuntu 24.04.5 LTS
Hypervisor and Version | Server Vendor and Model
not needed
Browser and version
not needed
Acknowledgements
Describe the bug
Environment
UTMStack Agent: 11.1.4
OS: Ubuntu Linux
Kernel: 6.8.0-142-generic
auditctl: 3.1.2
Docker Swarm environment
Issue
When the audit rule
utmstack_privis enabled:-a always,exit -F arch=b64 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv
-a always,exit -F arch=b32 -S setuid,setgid,setreuid,setregid,setresuid,setresgid -F auid>=1000 -k utmstack_priv
the agent logs:
auditd: queue full, dropping event
Kernel audit status shows:
lost 0
so the drops happen inside the UTMStack agent collector.
Evidence
ausearch -k utmstack_priv shows mainly:
comm="runc:[2:INIT]"
exe="/runc"
Executable summary:
82 /runc
Removing only the utmstack_priv rule stops the queue full errors immediately.
All other audit rules continue working normally.
Expected behavior
The agent should handle high-volume audit events without dropping messages, or provide a way to filter noisy container runtime events.
Question
Is this a known limitation of the auditd collector?
Should Docker/runc generated privilege-change events be filtered by default?
Regression Issue
Expected Behavior
No queue full
Current Behavior
queue full
Reproduction Steps
See description of bug
Possible Solution
No response
Additional Information/Context
No response
UTMStack Version
11.2.14
Operating System and version
Ubuntu 24.04.5 LTS
Hypervisor and Version | Server Vendor and Model
not needed
Browser and version
not needed