Linux audit files to see who made changes to a file

  2007-03-21 06:30:04
This is one of the key questions asked by new admins - How do I audit file events such as read / write etc? How can I use audit to see who changed a file in Linux?

The answer is to use2.6 kernel's audit system. Modern Linux kernel (2.6.x) comes with auditd daemon. It's responsible for writing audit records to the disk. During startup, the rules in /etc/audit.rules are read by this daemon. You can open /etc/audit.rules file and make changes such as setup audit file log location and other option. The default file is good enough to get started with auditd. 
  PNG Image  PNG Image  PNG Image
  Related tags  


This particular article has been collected via RSS syndication. We apologize if it's too brief.
If You wish to publish articles on LinuxStreet.net please contact us.


  Similar articles found on LinuxStreet  
ImageHow to convert PDF files to HTML or XML files in openSUSE
ImageTips from an RHCE: Visualizing audit logs with mkbar
ImageCLI Magic: Zip your files across the network with Woof
Image14 of the Best Free Linux File Managers
Image14 of the Best Free Linux File Managers
Imagexmldiff patches XML files by sending just the changes
ImageEfficient rsyncrypto hides remote sync data
ImageWhen files disappear, Magic Rescue saves the day
ImageEdit and compare giant binary files with lfhex
ImagePeaZip: Robust But Easy OSS File Management, Compression and Archiving

Leave a comment on this article


Captcha

  
Check this if the code you see is not readable and resubmit the form.
(Data you entered will be preserved)



  

Comments (0)