Things that need to be done:
===========================
1.2.7 - parse library
* Add dispatcher to reconfigure
* Add disp_qos to reconfigure
* Send sighup to child when no change in dispatcher
* Add subject information to audit internal messages
* Consolidate time code between start and end into ausearch-time.c
* Fix ausearch -ts today 11:50:00 to work (#191394)
* Do other time consolidation like omitting seconds
* Consolidate parsing code between libaudit and auditd-conf.c
* Change ausearch to output name="" unless its a real null. (mount) ausearch-report.c, 523. FIXME

1.2.8 - parse library
* make ausearch library for third party parsing API
* Success cb enum w/unset - adjust avc parsing to preserve syscall unless unset
* Avc messages should be linked list in ausearch & aureport
* Make sure there is a way to extract raw records with ausearch
* Ausearch make listing message types logical
* Aureport range of time in summary maybe should be what's req if -ts or -te
* Add keywords for time: this-week, this-month, last-boot, last-load, last-relabel.
* Add --since to replace -ts & -te. Will set -te to now 
* Change python to allow NULL param passing
* add more man pages
* Fix files with relative name in path record to have full path may have to combine cwd record with path
* Possibly do equivalent of "tail -f"

1.3 - event dispatcher
* Remove deprecated functions
* Bump soname number ???
* Don't audit the audispd program
* More audit dispatcher program & plugin framework updates
more plugins
* aureport get specific reports working

1.4
auditctl session id, pgid
Add counting semaphore to control internal queue depth
auditctl should ignore invalid arches for rules
Look at supporting binary formats
Remove evil getopt cruft in auditctl

1.5
look at config changed report to see if an action can be added 
Add scheduling options: strict, relaxed, loose (determines user space queueing)
Add exec option to action handlers
Parser should allow more than 1 arg after option - eg EXEC /usr/local/script
Add config option media: syslog, file, socket, dbus
Allow users to specify message types to be kept for logging
Allow users to specify fields to be kept for logging

1.6
Pretty Print ausearch messages
audit explorer gui
create responder to potential security incidents

IN THE DISTANT FUTURE:
Look at modifying kernel rule matcher to do: first match & match all 
Consider creating way to interactively delete rules by menu
Create a rule builder GUI
