All of lore.kernel.org
 help / color / mirror / Atom feed
* Using audit as extended inotify
@ 2015-07-27 23:30 Tyler Hardin
  2015-07-28 19:30 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Tyler Hardin @ 2015-07-27 23:30 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 357 bytes --]

I want to monitor file and directory creation, modification, and deletion
on some large subtrees (/etc/, /usr/share/, and ~/.config/). And I want the
name of the executable that caused the event. The purpose will be to
facilitate cruft detection and removal.

Can audit do this? Will using it to do this with such large subtrees become
a performance issue?

[-- Attachment #1.2: Type: text/html, Size: 403 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2015-07-28 19:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-07-27 23:30 Using audit as extended inotify Tyler Hardin
2015-07-28 19:30 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.