"Watch"ing a directory

Wieprecht, Karen M. Karen.Wieprecht at jhuapl.edu
Wed Aug 22 20:37:21 UTC 2007


We catch failures to cd into a directory with the rule "-a exit,always
-S all -F exit=-13"

Perhaps this captures too much, but it does seem to get the failed cd
attempts.  

Karen Wieprecht





More information about the Linux-audit mailing list