Auditing file access below a directory

Matt Anderson mra at hp.com
Wed Nov 16 23:21:34 UTC 2005


Mont Rothstein wrote:
> I am trying to determine if it is possible to audit all file access under a
> directory for all users.
> 
> I've been looking at auditd/auditctl and it seems like only individual files
> or directories can be watched, but not directory trees.
> 
> My current work around is to audit the gid of the default group for all of
> the users I care about (accessing the server as a file server via samba).
> 
> This is obviously not ideal.
> 
> Does anyone know if there is a way to do this?
> 
> Thanks,
> -Mont
> 
> P.S. This seemed to be the appropriate list for this. If it isn't I
> apologize.

This is perhaps a better list for your question.




More information about the fedora-selinux-list mailing list