From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Exclusion with recursive watch Date: Thu, 19 Feb 2009 13:43:11 -0500 Message-ID: <200902191343.11497.sgrubb@redhat.com> References: <4620668FFAA3D5458A691287D9DDAD11014C81ED@zrtphxm2.corp.nortel.com> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <4620668FFAA3D5458A691287D9DDAD11014C81ED@zrtphxm2.corp.nortel.com> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Thursday 19 February 2009 10:30:05 am Ameel Kamboh wrote: > -w /etc -p aw > > I would like to add an exception not to watch "/etc/mydir". > I know that audit 1.6 will watch /etc and all subdirs within that. > Is there a way I can add this exception? Not today. That is a kernel issue. Al corrected this in a patch that should have landed in the 2.6.29 kernel. I believe this will also be fixed in the next RHEL kernel. -Steve