<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Linux audit files to see who made changes to a file</title> <atom:link href="http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: John Gonzalez</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-176191</link> <dc:creator>John Gonzalez</dc:creator> <pubDate>Tue, 29 Nov 2011 23:55:07 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-176191</guid> <description>Thank You...!!!</description> <content:encoded><![CDATA[<p>Thank You&#8230;!!!</p> ]]></content:encoded> </item> <item><title>By: ceooph</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-175888</link> <dc:creator>ceooph</dc:creator> <pubDate>Mon, 21 Nov 2011 09:15:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-175888</guid> <description>Hi,
Thanks for this article and your whole site. I have a problem with auditd.
Can you audit a directory (yes) and all subdirectory ??
I want to audit a complete map point with folder, sub-folder, sub-sub-folder, ...
Thanks a lot for your help</description> <content:encoded><![CDATA[<p>Hi,<br
/> Thanks for this article and your whole site. I have a problem with auditd.<br
/> Can you audit a directory (yes) and all subdirectory ??<br
/> I want to audit a complete map point with folder, sub-folder, sub-sub-folder, &#8230;</p><p>Thanks a lot for your help</p> ]]></content:encoded> </item> <item><title>By: Prashant</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-174917</link> <dc:creator>Prashant</dc:creator> <pubDate>Mon, 17 Oct 2011 05:48:23 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-174917</guid> <description>Hi Sandy,
Were you about to get the answer for your query..
As even I want to get statistics on NFS / CIFS / FTP etc..
please let me know if you got any tips !
thnx
Prashant</description> <content:encoded><![CDATA[<p>Hi Sandy,</p><p>Were you about to get the answer for your query..<br
/> As even I want to get statistics on NFS / CIFS / FTP etc..<br
/> please let me know if you got any tips !</p><p>thnx<br
/> Prashant</p> ]]></content:encoded> </item> <item><title>By: Funutation</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-174811</link> <dc:creator>Funutation</dc:creator> <pubDate>Thu, 13 Oct 2011 17:45:04 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-174811</guid> <description>anyone know whether SELinux includes these features?  I assume that it does, and does even more but I cannot find details (easily :-)
thanx</description> <content:encoded><![CDATA[<p>anyone know whether SELinux includes these features?  I assume that it does, and does even more but I cannot find details (easily :-)</p><p>thanx</p> ]]></content:encoded> </item> <item><title>By: dreamingkat</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-172368</link> <dc:creator>dreamingkat</dc:creator> <pubDate>Sat, 09 Jul 2011 08:10:32 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-172368</guid> <description>according to the man page, a isn&#039;t for append, it&#039;s for attribute changes.</description> <content:encoded><![CDATA[<p>according to the man page, a isn&#8217;t for append, it&#8217;s for attribute changes.</p> ]]></content:encoded> </item> <item><title>By: Tha_Duck</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-171564</link> <dc:creator>Tha_Duck</dc:creator> <pubDate>Thu, 26 May 2011 11:38:30 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-171564</guid> <description># auditctl -w /tmp -p e -k webserver-watch-tmp
Shouldn&#039;t that be:
# auditctl -w /tmp -p x -k webserver-watch-tmp
?</description> <content:encoded><![CDATA[<p># auditctl -w /tmp -p e -k webserver-watch-tmp</p><p>Shouldn&#8217;t that be:<br
/> # auditctl -w /tmp -p x -k webserver-watch-tmp</p><p>?</p> ]]></content:encoded> </item> <item><title>By: David</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-171509</link> <dc:creator>David</dc:creator> <pubDate>Mon, 23 May 2011 21:35:09 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-171509</guid> <description>I&#039;d change the permissions on the PNG files to read-only - possibly by changing the extended attributes if necessary - and see what breaks. Might have to change the directory permissions if the mysterious program is actually creating a new file and moving deleting the old one - as these steps don&#039;t require file permissions, just directory permissions.</description> <content:encoded><![CDATA[<p>I&#8217;d change the permissions on the PNG files to read-only &#8211; possibly by changing the extended attributes if necessary &#8211; and see what breaks. Might have to change the directory permissions if the mysterious program is actually creating a new file and moving deleting the old one &#8211; as these steps don&#8217;t require file permissions, just directory permissions.</p> ]]></content:encoded> </item> <item><title>By: Cristian Rusu</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-170952</link> <dc:creator>Cristian Rusu</dc:creator> <pubDate>Wed, 27 Apr 2011 07:52:36 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-170952</guid> <description>Hello
Is there any way to figure out what php script modified a file on the system?
I got a bug where all the images in some folders are converted to an black empty png and I can&#039;t figure out what does this for months.
Thank you for any hint
Cris</description> <content:encoded><![CDATA[<p>Hello</p><p>Is there any way to figure out what php script modified a file on the system?<br
/> I got a bug where all the images in some folders are converted to an black empty png and I can&#8217;t figure out what does this for months.</p><p>Thank you for any hint</p><p>Cris</p> ]]></content:encoded> </item> <item><title>By: joe</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-170209</link> <dc:creator>joe</dc:creator> <pubDate>Mon, 21 Mar 2011 17:43:55 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-170209</guid> <description>Daren Tay
For SU install sudo and which uses su log.</description> <content:encoded><![CDATA[<p>Daren Tay<br
/> For SU install sudo and which uses su log.</p> ]]></content:encoded> </item> <item><title>By: DarenTay</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-169170</link> <dc:creator>DarenTay</dc:creator> <pubDate>Fri, 25 Feb 2011 08:04:58 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-169170</guid> <description>If a user su to root, how do we manage that? Can we identify who&#039;s the original user?</description> <content:encoded><![CDATA[<p>If a user su to root, how do we manage that? Can we identify who&#8217;s the original user?</p> ]]></content:encoded> </item> <item><title>By: Roumen Semov</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-163775</link> <dc:creator>Roumen Semov</dc:creator> <pubDate>Thu, 16 Dec 2010 00:39:18 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-163775</guid> <description>Hmmm, appending text to a watched file does not show up in the audit logs:
echo &#039;hello world&#039; &gt;&gt; /etc/passwd
Any idea why?</description> <content:encoded><![CDATA[<p>Hmmm, appending text to a watched file does not show up in the audit logs:<br
/> echo &#8216;hello world&#8217; &gt;&gt; /etc/passwd<br
/> Any idea why?</p> ]]></content:encoded> </item> <item><title>By: Sandy</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-162945</link> <dc:creator>Sandy</dc:creator> <pubDate>Sun, 12 Dec 2010 19:42:48 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-162945</guid> <description>Does auditd work over NFS ? . I mean, if any one read/write a file through NFS, The audit system will log them?? I have not been able to configure this. auditd  captures read/write access from FTP and even CIFS - but not from NFS ? Anyone has any Clue ?</description> <content:encoded><![CDATA[<p>Does auditd work over NFS ? . I mean, if any one read/write a file through NFS, The audit system will log them?? I have not been able to configure this. auditd  captures read/write access from FTP and even CIFS &#8211; but not from NFS ? Anyone has any Clue ?</p> ]]></content:encoded> </item> <item><title>By: Aldian</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-161453</link> <dc:creator>Aldian</dc:creator> <pubDate>Mon, 22 Nov 2010 10:34:23 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-161453</guid> <description>You forgot to explain how to stop monitoring once not needed anymore</description> <content:encoded><![CDATA[<p>You forgot to explain how to stop monitoring once not needed anymore</p> ]]></content:encoded> </item> <item><title>By: Yzhar</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-160964</link> <dc:creator>Yzhar</dc:creator> <pubDate>Thu, 11 Nov 2010 10:27:19 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-160964</guid> <description>I&#039;m a Varins inc eng that had research this stuff for a while.
Unix (any), lacks such abilities and the best it can do is audit pre define objects.
scale is poor and some file operations are missing.
We have successfully build such framework (for about any unix platforms).
it is running on hundreds production sites for 3 years now. and I can tell you it wasn&#039;t easy.
I don&#039;t want to sound like a sales man (I&#039;m not), but hope I can save you some time if you are looking for such solution.
btw,
very nice article.</description> <content:encoded><![CDATA[<p>I&#8217;m a Varins inc eng that had research this stuff for a while.</p><p>Unix (any), lacks such abilities and the best it can do is audit pre define objects.<br
/> scale is poor and some file operations are missing.</p><p>We have successfully build such framework (for about any unix platforms).<br
/> it is running on hundreds production sites for 3 years now. and I can tell you it wasn&#8217;t easy.</p><p>I don&#8217;t want to sound like a sales man (I&#8217;m not), but hope I can save you some time if you are looking for such solution.</p><p>btw,<br
/> very nice article.</p> ]]></content:encoded> </item> <item><title>By: Dave Marcus</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-160085</link> <dc:creator>Dave Marcus</dc:creator> <pubDate>Thu, 07 Oct 2010 21:07:11 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-160085</guid> <description>Is there anyway to place an audit on a directory?  And yes it&#039;s a very good article, I have it bookmarked.</description> <content:encoded><![CDATA[<p>Is there anyway to place an audit on a directory?  And yes it&#8217;s a very good article, I have it bookmarked.</p> ]]></content:encoded> </item> <item><title>By: nima0102</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-159767</link> <dc:creator>nima0102</dc:creator> <pubDate>Tue, 21 Sep 2010 13:51:57 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-159767</guid> <description>Good Article :):)</description> <content:encoded><![CDATA[<p>Good Article :):)</p> ]]></content:encoded> </item> <item><title>By: Hello1971</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157989</link> <dc:creator>Hello1971</dc:creator> <pubDate>Wed, 14 Jul 2010 02:03:30 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157989</guid> <description>Hi, Did this work on exported directory. I mean, if any one read/write a file through NFS, The audit system will log them??</description> <content:encoded><![CDATA[<p>Hi, Did this work on exported directory. I mean, if any one read/write a file through NFS, The audit system will log them??</p> ]]></content:encoded> </item> <item><title>By: Jagadeesh</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157577</link> <dc:creator>Jagadeesh</dc:creator> <pubDate>Fri, 09 Jul 2010 05:07:05 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157577</guid> <description>Hi,
This is very nice article. In my company we have NFS mounted home directories. Anyone can access files from anybody&#039;s home. This will help me monitoring who comes to my home :-)
Thanks for this article</description> <content:encoded><![CDATA[<p>Hi,</p><p>This is very nice article. In my company we have NFS mounted home directories. Anyone can access files from anybody&#8217;s home. This will help me monitoring who comes to my home :-)</p><p>Thanks for this article</p> ]]></content:encoded> </item> <item><title>By: Anonymous</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157291</link> <dc:creator>Anonymous</dc:creator> <pubDate>Mon, 05 Jul 2010 21:04:14 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-157291</guid> <description>is it possible to use it from NIS.. we use ypcat</description> <content:encoded><![CDATA[<p>is it possible to use it from NIS.. we use ypcat</p> ]]></content:encoded> </item> <item><title>By: asdasdsd</title><link>http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-152421</link> <dc:creator>asdasdsd</dc:creator> <pubDate>Tue, 22 Dec 2009 13:25:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html#comment-152421</guid> <description>/edit:
# ausearch -f etc_passwd
\
Had to escape the greater and less than sign because this comments section thought that it was some HTML!</description> <content:encoded><![CDATA[<p>/edit:<br
/> # ausearch -f etc_passwd<br
/> \</p><p>Had to escape the greater and less than sign because this comments section thought that it was some HTML!</p> ]]></content:encoded> </item> </channel> </rss>
