On my two SLES 11 SP2 servers event daemon is not working correctly.
Script “/usr/sbin/aa-eventd” is parsing system log files (audit.log + messages) looking for “$logmsg =~ /APPARMOR/;” but those events appear in fact in low case.
Changing the reg exp comparsion is not solving the problem. Event daemon is creating event.db properly and even sending e-mail notification but only during start up process. After that is stopping processing new events.
rpm -qa | grep armor