audit.56 merged with audit-2.6.git

Steve Grubb sgrubb at redhat.com
Thu Jun 9 16:09:37 UTC 2005


On Thursday 09 June 2005 11:13, Timothy R. Chavez wrote:
> Have you tried using the syscall (inode,dev)-based filter rules?

Files that are deleted and created can have new inode numbers. Examples are 
rotating audit logs and updating /etc/shadow.

-Steve




More information about the Linux-audit mailing list