# /dev/shm/var/lib/solera
-A exit,never -F arch=b64 -F dir=/dev/shm/var/lib/solera
# /pfs
-A exit,never -F arch=b64 -F dir=/pfs
Add the following lines
# Exclude all files in /var/lib/solera
-A exit,never -F arch=b64 -F dir=/var/lib/solera
Restart auditd and syslog-ng with:
service auditd restart;service syslog-ng restart
The /var/log/audit/audit.log will be rotated and start with an empty file.