I am configuring our auditing service to send logs through rsyslog. While tinkering around, I was able to stop and start auditing from the command line as the root user. Is there a way to prevent anyone including root from stopping the audit service unless system is rebooted into single user mode? Thanks, Paul M. Whitney -- redhat-list mailing list unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe https://www.redhat.com/mailman/listinfo/redhat-list