audit rules watching paths

Warron French warron.french at gmail.com
Sun Mar 12 04:48:53 UTC 2017


I know that I can add to the audit.rules file a rule like

-w /etc/ -p rawx -k watch_Etc

But how far down will this sort of audit rule monitor /etc/?  How many 
levels deep?


Thanks.




More information about the Linux-audit mailing list