Alternatives to auditd and inotify for monitoring file deletion

Posted by Tola Odejayi on Server Fault See other posts from Server Fault or by Tola Odejayi
Published on 2012-10-01T18:08:01Z Indexed on 2012/11/05 5:03 UTC
Read the original article Hit count: 439

Filed under:
|
|

I'm trying to figure out which processes are deleting files from a specific directory on my CentOS server.

I looked at inotify, but all this does is to tell me how many file deletions are occurring; it does not tell me what process run by which user did the deletions, nor does it tell me when they happened.

I also tried auditd, but I have had no luck in getting it set up on my server.

Does anyone have any other tool they can suggest that will do this?

© Server Fault or respective owner

Related posts about monitoring

Related posts about inotify