All of lore.kernel.org
 help / color / mirror / Atom feed
* File Monitoring
@ 2006-07-24 16:11 Steve
  0 siblings, 0 replies; 4+ messages in thread
From: Steve @ 2006-07-24 16:11 UTC (permalink / raw)
  To: linux-audit

I am monitoring open syscalls on /etc/shadow and am receiving alerts 
that I would like to suppress.  Is it possible to exclude alerts for 
files opened with particular commands?  For example, xlock opening the 
shadow file?  I didn't see an option like this in the auditctl man page, 
but I know those pages may be outdated.

Thanks,
Steve

^ permalink raw reply	[flat|nested] 4+ messages in thread
* File monitoring
@ 2007-01-27 20:31 Jan Engelhardt
  2007-01-27 21:41 ` Trond Myklebust
  2007-01-28 22:49 ` Bill Rugolsky Jr.
  0 siblings, 2 replies; 4+ messages in thread
From: Jan Engelhardt @ 2007-01-27 20:31 UTC (permalink / raw)
  To: nfs

Hello list,


as part of implementing a netboot solution, I observe that the client 
pulls about 128 MB of data (measured in iptraf, so it includes 
IPv4 headers too). You probably agree that this contributes to a boot 
that could possibly be sped up (even if the same distribution was to 
read from local disk). I wonder what files it actually accesses. Is 
there some utility to get a listing of all the files that were accessed? 
tcpdump provides a nice hint, e.g.

21:29:09.877364 IP 192.168.222.34.3204330825 > 192.168.222.1.2049: 116 
lookup fh 
Unknown/0100000100160005118A180EF8B50D0D000000000000001068616C2D6765742D  
"hal-get-property"

But at best I'd like to have the full pathname (to distinguish the 
fictional case /bin/cat vs /usr/bin/cat)


	-`J'
-- 

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2007-01-28 22:49 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-07-24 16:11 File Monitoring Steve
  -- strict thread matches above, loose matches on Subject: below --
2007-01-27 20:31 File monitoring Jan Engelhardt
2007-01-27 21:41 ` Trond Myklebust
2007-01-28 22:49 ` Bill Rugolsky Jr.

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.