Things that need to be done:
===========================
1.0.4
ausearch should show a map of what logs have what times

1.1
auditctl should ignore invalid arches for rules
Under what circumstances do files have relative name in path record - ausearch may have to combine cwd record with path to do file searches

1.2
Add scheduling options: strict, relaxed, loose (determines user space queueing)
Add exec option to action handlers
Parser should allow more than 1 arg after option - eg EXEC /usr/local/script
Add config option media: syslog, file, socket, dbus
auditctl trigger on context
auditctl session id, pgid
ausearch on context
make ausearch library for third party parsing API
Add counting semaphore to control internal queue depth

1.3
Look at adding XML & binary formats
Remove evil getopt cruft in auditctl
Pretty Print ausearch messages
Allow users to specify message types to be kept for logging
Allow users to specify fields to be kept for logging
Add rotate on startup option.
Look at modifying rule matcher to do: first match & match all 

IN THE DISTANT FUTURE:
Allow users to label syscall event rules in auditctl
Look into preventing duplicate rules 
Consider creating way to interactively delete rules by menu
Create a rule builder GUI
