File Monitoring

Steve m6x at ornl.gov
Mon Jul 24 16:11:31 UTC 2006


I am monitoring open syscalls on /etc/shadow and am receiving alerts 
that I would like to suppress.  Is it possible to exclude alerts for 
files opened with particular commands?  For example, xlock opening the 
shadow file?  I didn't see an option like this in the auditctl man page, 
but I know those pages may be outdated.

Thanks,
Steve




More information about the Linux-audit mailing list