public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Audit watches on NFS mounts
@ 2016-10-20 14:42 Vaughn, Chad M
  2016-10-20 15:37 ` Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: Vaughn, Chad M @ 2016-10-20 14:42 UTC (permalink / raw)
  To: Steve Grubb, linux-audit@redhat.com

I noticed a weird behavior. I NFS mount /usr/local on my Redhat machines.

If I put a watch for a directory in that NFS mount:

-w /usr/local/mywatchdir/ -p rwxa -F exit!=-ENODATA -F success!=1 -k watch


On Redhat 6.4, I don't see audit events when trying to remove or change files in that dir.
On Redhat 6.8, I do see the audit events when trying to remove or changes files in that dir.

Any ideas of possible features added to auditd between those releases?  I would like to be able to speak to it for security audits.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2016-10-20 16:22 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-10-20 14:42 Audit watches on NFS mounts Vaughn, Chad M
2016-10-20 15:37 ` Steve Grubb
2016-10-20 16:10   ` EXTERNAL: " Vaughn, Chad M
2016-10-20 16:22     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox