I checked the var/log/audit.d directory and there were a few thousand 20mb save.* files which had basically filled up almost my entire disk space. ( > 50 gig worth)
We usually remove audit from our boxes, it’s resource intensive and as you saw can eat up some disk space too :). If you remove it yum won’t update (re-add) it later on.
to this
notify = “/usr/sbin/audbin -S /var/log/audit.d/save.%u -C -T 99% -N ‘rm -f %f’”;
Which should delete the latest save file, I also removed the “type = suspend” action from the action list which should keep it from suspending audit, as my disk is definately more than 1% used…