Further documentation of the 3 possible kernel value of the audit
command line option.
Signed-off-by: Eric Paris <eparis@redhat.com>
audit= [KNL] Enable the audit sub-system
Format: { "0" | "1" } (0 = disabled, 1 = enabled)
+ 0 - kernel audit is disabled and can not be enabled
+ until the next reboot
+ unset - kernel audit is initialized but disabled and
+ will be fully enabled by the userspace auditd.
+ 1 - kernel audit is initialized and partially enabled,
+ storing at most audit_backlog_limit messages in
+ RAM until it is fully enabled by the userspace
+ auditd.
Default: unset
audit_backlog_limit= [KNL] Set the audit queue size limit.