Alternatives to auditd and inotify for monitoring file deletion
Posted
by
Tola Odejayi
on Server Fault
See other posts from Server Fault
or by Tola Odejayi
Published on 2012-10-01T18:08:01Z
Indexed on
2012/11/05
5:03 UTC
Read the original article
Hit count: 443
I'm trying to figure out which processes are deleting files from a specific directory on my CentOS server.
I looked at inotify
, but all this does is to tell me how many file deletions are occurring; it does not tell me what process run by which user did the deletions, nor does it tell me when they happened.
I also tried auditd
, but I have had no luck in getting it set up on my server.
Does anyone have any other tool they can suggest that will do this?
© Server Fault or respective owner