It seems, if audit itself is not installed and therefore nothing listens to the messages from the kernel's audit subsystem, the latter spams the kernel log with such messages. Let us make them debug-level and thus invisible by default. http://bugs.rosalinux.ru/show_bug.cgi?id=6235 http://bugs.rosalinux.ru/show_bug.cgi?id=6459 diff --git a/kernel/audit.c b/kernel/audit.c index 1c13e42..56270ce 100644 --- a/kernel/audit.c +++ b/kernel/audit.c @@ -396,7 +396,7 @@ static void audit_printk_skb(struct sk_buff *skb) if (nlh->nlmsg_type != AUDIT_EOE) { if (printk_ratelimit()) - pr_notice("type=%d %s\n", nlh->nlmsg_type, data); + pr_debug("type=%d %s\n", nlh->nlmsg_type, data); else audit_log_lost("printk limit exceeded"); }