audit_receive_filter — apply all rules to the specified message type
int audit_receive_filter ( | int | type, |
| int | pid, | |
| int | uid, | |
| int | seq, | |
| void * | data, | |
| size_t | datasz, | |
| uid_t | loginuid, | |
| u32 | sessionid, | |
| u32 | sid); |
typeaudit message type
pidtarget pid for netlink audit messages
uidtarget uid for netlink audit messages
seqnetlink audit message sequence (serial) number
datapayload data
dataszsize of payload data
loginuidloginuid of sender
sessionidsessionid for netlink audit message
sidSE Linux Security ID of sender