I was playing with audit rules using keys with spaces. Is the following expected (ignore the logic; was just testing the returns)? # auditctl -l -k lsmod LIST_RULES: exit,always watch=/sbin/lsmod perm=x key=lsmod kernel LIST_RULES: exit,always watch=/bin/ping perm=x key=lsmod ping Thx, LCB -- LC (Lenny) Bruzenak lenny at magitekltd.com