Auditing file access below a directory

Mont Rothstein mont.rothstein at gmail.com
Wed Nov 16 23:16:33 UTC 2005


I am trying to determine if it is possible to audit all file access under a
directory for all users.

I've been looking at auditd/auditctl and it seems like only individual files
or directories can be watched, but not directory trees.

My current work around is to audit the gid of the default group for all of
the users I care about (accessing the server as a file server via samba).

This is obviously not ideal.

Does anyone know if there is a way to do this?

Thanks,
-Mont

P.S. This seemed to be the appropriate list for this. If it isn't I
apologize.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20051116/e1e39b52/attachment.htm>


More information about the fedora-selinux-list mailing list